ip6t-firewall-gateway,ipt-firewall-gateway: add missing rules for wireguard VPN connection.
This commit is contained in:
parent
338b2cf8d7
commit
9967a2dddc
@ -936,9 +936,11 @@ echo_done
|
|||||||
echononl "\tPermit all traffic through WireGuard lines.."
|
echononl "\tPermit all traffic through WireGuard lines.."
|
||||||
for _wg_if in ${wg_if_arr[@]} ; do
|
for _wg_if in ${wg_if_arr[@]} ; do
|
||||||
$ip6t -A INPUT -i $_wg_if -m conntrack --ctstate NEW -j ACCEPT
|
$ip6t -A INPUT -i $_wg_if -m conntrack --ctstate NEW -j ACCEPT
|
||||||
|
$ip6t -A OUTPUT -o $_wg_if -m conntrack --ctstate NEW -j ACCEPT
|
||||||
if $kernel_forward_between_interfaces ; then
|
if $kernel_forward_between_interfaces ; then
|
||||||
for _local_dev in ${local_if_arr[@]} ; do
|
for _local_dev in ${local_if_arr[@]} ; do
|
||||||
$ip6t -A FORWARD -i $_wg_if -o $_local_dev -m conntrack --ctstate NEW -j ACCEPT
|
$ip6t -A FORWARD -i $_wg_if -o $_local_dev -m conntrack --ctstate NEW -j ACCEPT
|
||||||
|
$ip6t -A FORWARD -i $_local_dev -o $_wg_if -m conntrack --ctstate NEW -j ACCEPT
|
||||||
done
|
done
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
|
@ -1571,9 +1571,11 @@ echo_done
|
|||||||
echononl "\tPermit all traffic through WireGuard lines.."
|
echononl "\tPermit all traffic through WireGuard lines.."
|
||||||
for _wg_if in ${wg_if_arr[@]} ; do
|
for _wg_if in ${wg_if_arr[@]} ; do
|
||||||
$ipt -A INPUT -i $_wg_if -m conntrack --ctstate NEW -j ACCEPT
|
$ipt -A INPUT -i $_wg_if -m conntrack --ctstate NEW -j ACCEPT
|
||||||
|
$ipt -A OUTPUT -o $_wg_if -m conntrack --ctstate NEW -j ACCEPT
|
||||||
if $kernel_activate_forwarding ; then
|
if $kernel_activate_forwarding ; then
|
||||||
for _local_dev in ${local_if_arr[@]} ; do
|
for _local_dev in ${local_if_arr[@]} ; do
|
||||||
$ipt -A FORWARD -i $_wg_if -o $_local_dev -m conntrack --ctstate NEW -j ACCEPT
|
$ipt -A FORWARD -i $_wg_if -o $_local_dev -m conntrack --ctstate NEW -j ACCEPT
|
||||||
|
$ipt -A FORWARD -i $_local_dev -o $_wg_if -m conntrack --ctstate NEW -j ACCEPT
|
||||||
done
|
done
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
|
Loading…
Reference in New Issue
Block a user