fix: output rules
This commit is contained in:
+2
-2
@@ -129,11 +129,11 @@ _nft_init() {
|
||||
_log "$TABLE: setting up base chains" "debug"
|
||||
nft add chain ip "$TABLE" prerouting { type filter hook prerouting priority mangle \; policy accept \; } 2>/dev/null
|
||||
nft flush chain ip "$TABLE" prerouting
|
||||
nft add rule ip "$TABLE" prerouting fib daddr type local accept
|
||||
nft add rule ip "$TABLE" prerouting fib daddr type local accept 2>/dev/null
|
||||
|
||||
nft add chain ip "$TABLE" output { type route hook output priority -150 \; policy accept \; } 2>/dev/null
|
||||
nft flush chain ip "$TABLE" output
|
||||
nft add rule ip "$TABLE" output fib daddr type local accept
|
||||
nft add rule ip "$TABLE" output fib daddr type local accept 2>/dev/null
|
||||
|
||||
local mark_hex=$(printf '0x%x' "$TPROXY_MARK")
|
||||
_log "route: configuring table $RT_TABLE, mark $mark_hex" "debug"
|
||||
|
||||
Reference in New Issue
Block a user