mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-04-09 10:35:53 +02:00
firewall: Move the IPS after the NAT marking
This is because we might still land in the scenario where Suricata crashes and NFQUEUE will simply ACCEPT all packets which will terminate the processing of the mangle table. Therefore the NFQUEUE rule should be the last one so that we never skip any of the other processing. Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
This commit is contained in:
@@ -221,13 +221,6 @@ iptables_init() {
|
||||
iptables -A FORWARD -i tun+ -j OVPNBLOCK
|
||||
iptables -A FORWARD -o tun+ -j OVPNBLOCK
|
||||
|
||||
# IPS (Suricata) chains
|
||||
iptables -t mangle -N IPS
|
||||
|
||||
for chain in PREROUTING POSTROUTING; do
|
||||
iptables -t mangle -A "${chain}" -j IPS
|
||||
done
|
||||
|
||||
# OpenVPN transfer network translation
|
||||
iptables -t nat -N OVPNNAT
|
||||
iptables -t nat -A POSTROUTING -j OVPNNAT
|
||||
@@ -382,6 +375,13 @@ iptables_init() {
|
||||
-m mark --mark "0x04000000/${NAT_MASK}" -j SNAT --to-source "${ORANGE_ADDRESS}"
|
||||
fi
|
||||
|
||||
# IPS (Suricata) chains
|
||||
iptables -t mangle -N IPS
|
||||
|
||||
for chain in PREROUTING POSTROUTING; do
|
||||
iptables -t mangle -A "${chain}" -j IPS
|
||||
done
|
||||
|
||||
# RED chain, used for the red interface
|
||||
iptables -N REDINPUT
|
||||
iptables -A INPUT -j REDINPUT
|
||||
|
||||
Reference in New Issue
Block a user