Commit 4a0ebff3 authored by nanahira's avatar nanahira

fix chnroute reverse

parent 1d3c1dd3
...@@ -46,7 +46,7 @@ ...@@ -46,7 +46,7 @@
[Service] [Service]
Type=oneshot Type=oneshot
ExecStart={{ansible_user_dir}}/nextgen-router/scripts/global-setup.sh ExecStart={{ansible_user_dir}}/nextgen-router/scripts/global-postup.sh
[Install] [Install]
WantedBy=mutli-user.target WantedBy=mutli-user.target
...@@ -55,7 +55,7 @@ ...@@ -55,7 +55,7 @@
- name: systemd - name: systemd
become: global-postup systemd enable become: global-postup systemd enable
systemd: systemd:
name: regenerate_ssh_host_keys name: railgun-global-setup
enabled: true enabled: true
daemon_reload: '{{global_systemd_result.changed}}' daemon_reload: '{{global_systemd_result.changed}}'
- name: mycard ipset create - name: mycard ipset create
......
...@@ -44,5 +44,5 @@ interface_switch_chnroute() { ...@@ -44,5 +44,5 @@ interface_switch_chnroute() {
IPSET=$2 IPSET=$2
MARK=$3 MARK=$3
ipset create "$IPSET" hash:net maxelem 1000000 || true ipset create "$IPSET" hash:net maxelem 1000000 || true
iptables -t mangle "$OPTION" NEXTGEN_SWITCH -m mark --mark 0 -m set --match-set "$IPSET" src -m set --match-set chnrouter dst -j CONNMARK --set-xmark "$MARK" iptables -t mangle "$OPTION" NEXTGEN_SWITCH -m mark --mark 0 -m set --match-set "$IPSET" src -m set --match-set chnroute_reverse dst -j CONNMARK --set-xmark "$MARK"
} }
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment