Move ipsec postrouting rules to a own chain.

This commit is contained in:
Arne Fitzenreiter
2009-12-21 02:26:09 +01:00
parent 72c63a1531
commit b68e5c14b6
3 changed files with 8 additions and 5 deletions

View File

@@ -167,7 +167,9 @@ case "$1" in
/sbin/iptables -A INPUT -j OPENSSLVIRTUAL -m comment --comment "OPENSSLVIRTUAL INPUT"
/sbin/iptables -A FORWARD -j IPSECVIRTUAL -m comment --comment "IPSECVIRTUAL FORWARD"
/sbin/iptables -A FORWARD -j OPENSSLVIRTUAL -m comment --comment "OPENSSLVIRTUAL FORWARD"
/sbin/iptables -t nat -N IPSECPOSTROUTING
/sbin/iptables -t nat -A POSTROUTING -j IPSECPOSTROUTING
# Outgoing Firewall
/sbin/iptables -A FORWARD -j OUTGOINGFW