mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-04-27 19:23:24 +02:00
rules.pl: Move to ipset based data for location based firewall rules.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org> Reviewed-by: Peter Müller <peter.mueller@ipfire.org> Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
This commit is contained in:
committed by
Peter Müller
parent
0df1d268ed
commit
07106467b8
@@ -466,7 +466,7 @@ sub get_address
|
||||
# Get external interface.
|
||||
my $external_interface = &get_external_interface();
|
||||
|
||||
push(@ret, ["-m geoip --src-cc $value", "$external_interface"]);
|
||||
push(@ret, ["-m set --match-set CC_$value src", "$external_interface"]);
|
||||
}
|
||||
|
||||
# Handle rule options with a location as target.
|
||||
@@ -476,7 +476,7 @@ sub get_address
|
||||
# Get external interface.
|
||||
my $external_interface = &get_external_interface();
|
||||
|
||||
push(@ret, ["-m geoip --dst-cc $value", "$external_interface"]);
|
||||
push(@ret, ["-m set --match-set CC_$value dst", "$external_interface"]);
|
||||
}
|
||||
|
||||
# If nothing was selected, we assume "any".
|
||||
|
||||
Reference in New Issue
Block a user