[Unit] Description=Daemon for graphing traffic of subnet machines Requires=network-online.target bandwidthd-rotate.timer bandwidthd-webui.service [Service] User=bandwidthd Group=bandwidthd CapabilityBoundingSet=CAP_NET_RAW AmbientCapabilities=CAP_NET_RAW RestrictAddressFamilies=AF_UNIX AF_PACKET RestrictNamespaces=true PrivateDevices=true NoNewPrivileges=true PrivateTmp=true ProtectClock=true ProtectControlGroups=true ProtectHome=true ProtectKernelLogs=true ProtectKernelModules=true ProtectKernelTunables=true ProtectSystem=strict StateDirectory=bandwidthd RuntimeDirectory=bandwidthd ConfigurationDirectory=bandwidthd RestrictSUIDSGID=true SystemCallArchitectures=native RestrictRealtime=true LockPersonality=true MemoryDenyWriteExecute=true RemoveIPC=true UMask=066 ProtectHostname=true IPAddressDeny=any SystemCallFilter=@system-service SystemCallFilter=~@privileged ExecStart=/usr/bin/bandwidthd -D -c /etc/bandwidthd/bandwidthd.conf PIDFile=bandwidthd/bandwidthd.pid [Install] WantedBy=multi-user.target