fix: output rules
This commit is contained in:
+2
-2
@@ -129,11 +129,11 @@ _nft_init() {
|
|||||||
_log "$TABLE: setting up base chains" "debug"
|
_log "$TABLE: setting up base chains" "debug"
|
||||||
nft add chain ip "$TABLE" prerouting { type filter hook prerouting priority mangle \; policy accept \; } 2>/dev/null
|
nft add chain ip "$TABLE" prerouting { type filter hook prerouting priority mangle \; policy accept \; } 2>/dev/null
|
||||||
nft flush chain ip "$TABLE" prerouting
|
nft flush chain ip "$TABLE" prerouting
|
||||||
nft add rule ip "$TABLE" prerouting fib daddr type local accept
|
nft add rule ip "$TABLE" prerouting fib daddr type local accept 2>/dev/null
|
||||||
|
|
||||||
nft add chain ip "$TABLE" output { type route hook output priority -150 \; policy accept \; } 2>/dev/null
|
nft add chain ip "$TABLE" output { type route hook output priority -150 \; policy accept \; } 2>/dev/null
|
||||||
nft flush chain ip "$TABLE" output
|
nft flush chain ip "$TABLE" output
|
||||||
nft add rule ip "$TABLE" output fib daddr type local accept
|
nft add rule ip "$TABLE" output fib daddr type local accept 2>/dev/null
|
||||||
|
|
||||||
local mark_hex=$(printf '0x%x' "$TPROXY_MARK")
|
local mark_hex=$(printf '0x%x' "$TPROXY_MARK")
|
||||||
_log "route: configuring table $RT_TABLE, mark $mark_hex" "debug"
|
_log "route: configuring table $RT_TABLE, mark $mark_hex" "debug"
|
||||||
|
|||||||
Reference in New Issue
Block a user