mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-05-03 18:41:29 +02:00
iptables: Create OVPNNAT chain after CUSTOM* chains.
This commit is contained in:
@@ -90,11 +90,9 @@ iptables_init() {
|
||||
/sbin/iptables -N OUTGOINGFW
|
||||
/sbin/iptables -A OUTPUT -j OUTGOINGFW
|
||||
/sbin/iptables -t nat -N CUSTOMPREROUTING
|
||||
/sbin/iptables -t nat -N OVPNNAT
|
||||
/sbin/iptables -t nat -A PREROUTING -j CUSTOMPREROUTING
|
||||
/sbin/iptables -t nat -N CUSTOMPOSTROUTING
|
||||
/sbin/iptables -t nat -A POSTROUTING -j CUSTOMPOSTROUTING
|
||||
/sbin/iptables -t nat -A POSTROUTING -j OVPNNAT
|
||||
|
||||
# Guardian (IPS) chains
|
||||
/sbin/iptables -N GUARDIAN
|
||||
@@ -107,6 +105,10 @@ iptables_init() {
|
||||
/sbin/iptables -A ${i} -j OVPNBLOCK
|
||||
done
|
||||
|
||||
# OpenVPN transfer network translation
|
||||
/sbin/iptables -t nat -N OVPNNAT
|
||||
/sbin/iptables -t nat -A POSTROUTING -j OVPNNAT
|
||||
|
||||
# IPTV chains for IGMPPROXY
|
||||
/sbin/iptables -N IPTVINPUT
|
||||
/sbin/iptables -A INPUT -j IPTVINPUT
|
||||
|
||||
Reference in New Issue
Block a user