Commit 9b821997 authored by nanahira's avatar nanahira

fix create chain

parent 335d0f12
......@@ -20,7 +20,7 @@ $IPTABLES_EXEC -t nat -A POSTROUTING -m set --match-set mycard src -m set ! --ma
{% endfor %}
# chain for wg origin
# $IPTABLES_EXEC -t mangle -N NEXTGEN_ORIGIN
$IPTABLES_EXEC -t mangle -N NEXTGEN_ORIGIN
$IPTABLES_EXEC -t mangle -I PREROUTING -m mark --mark 0x0 ! -p ospf -j NEXTGEN_ORIGIN
{% for interface in masqInterfaces %}
$IPTABLES_EXEC -t mangle -A NEXTGEN_ORIGIN -i {{interface.name}} ! -p ospf -m set ! --match-set mycard src -j CONNMARK --set-xmark {{interface.mark}}
......@@ -29,7 +29,7 @@ $IPTABLES_EXEC -t mangle -A OUTPUT -m connmark --mark {{interface.mark}} -j CONN
# TODO: ip rule
# ip rule add pref 300 fwmark {{interface.mark}} lookup {{interface.mark}}
{% endfor %}
# $IPTABLES_EXEC -t mangle -N NEXTGEN_SWITCH
$IPTABLES_EXEC -t mangle -N NEXTGEN_SWITCH
$IPTABLES_EXEC -t mangle -A PREROUTING -m mark --mark 0x0 ! -p ospf -m set ! --match-set mycard dst -j NEXTGEN_SWITCH
$IPTABLES_EXEC -t mangle -I OUTPUT -m mark ! --mark 0 -j RETURN
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment