mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-04-28 03:33:25 +02:00
Pre-Firewall: added OVPNNAT to POSTROUTING Chain
This commit is contained in:
@@ -178,12 +178,14 @@ case "$1" in
|
|||||||
/sbin/iptables -N IPSECFORWARD
|
/sbin/iptables -N IPSECFORWARD
|
||||||
/sbin/iptables -N IPSECOUTPUT
|
/sbin/iptables -N IPSECOUTPUT
|
||||||
/sbin/iptables -N OPENSSLVIRTUAL
|
/sbin/iptables -N OPENSSLVIRTUAL
|
||||||
|
/sbin/iptables -N OVPNNAT
|
||||||
/sbin/iptables -A INPUT -j IPSECINPUT
|
/sbin/iptables -A INPUT -j IPSECINPUT
|
||||||
/sbin/iptables -A INPUT -j OPENSSLVIRTUAL -m comment --comment "OPENSSLVIRTUAL INPUT"
|
/sbin/iptables -A INPUT -j OPENSSLVIRTUAL -m comment --comment "OPENSSLVIRTUAL INPUT"
|
||||||
/sbin/iptables -A FORWARD -j IPSECFORWARD
|
/sbin/iptables -A FORWARD -j IPSECFORWARD
|
||||||
/sbin/iptables -A FORWARD -j OPENSSLVIRTUAL -m comment --comment "OPENSSLVIRTUAL FORWARD"
|
/sbin/iptables -A FORWARD -j OPENSSLVIRTUAL -m comment --comment "OPENSSLVIRTUAL FORWARD"
|
||||||
/sbin/iptables -A OUTPUT -j IPSECOUTPUT
|
/sbin/iptables -A OUTPUT -j IPSECOUTPUT
|
||||||
/sbin/iptables -t nat -N IPSECNAT
|
/sbin/iptables -t nat -N IPSECNAT
|
||||||
|
/sbin/iptables -t nat -A POSTROUTING -j OVPNNAT
|
||||||
/sbin/iptables -t nat -A POSTROUTING -j IPSECNAT
|
/sbin/iptables -t nat -A POSTROUTING -j IPSECNAT
|
||||||
|
|
||||||
# Outgoing Firewall
|
# Outgoing Firewall
|
||||||
|
|||||||
Reference in New Issue
Block a user