From 4dac5d86e426572618e0b8c6c4fbf7de8d3ac59c Mon Sep 17 00:00:00 2001 From: Gregor Kleen Date: Mon, 15 Nov 2021 23:45:54 +0059 Subject: vidhar: ... --- hosts/vidhar/default.nix | 25 +++++++++++++------------ 1 file changed, 13 insertions(+), 12 deletions(-) diff --git a/hosts/vidhar/default.nix b/hosts/vidhar/default.nix index a13398db..45953d93 100644 --- a/hosts/vidhar/default.nix +++ b/hosts/vidhar/default.nix @@ -106,23 +106,24 @@ ip46tables -A FORWARD -j nixos-fw-forward - ip46tables -t nat -D POSTROUTING -j nixos-fw-postrouting 2>/dev/null || true - ip46tables -t nat -F nixos-fw-postrouting 2>/dev/null || true - ip46tables -t nat -X nixos-fw-postrouting 2>/dev/null || true + ip46tables -t nat -D POSTROUTING -j nixos-fw-postrouting-nat 2>/dev/null || true + ip46tables -t nat -F nixos-fw-postrouting-nat 2>/dev/null || true + ip46tables -t nat -X nixos-fw-postrouting-nat 2>/dev/null || true - ip46tables -t nat -N nixos-fw-postrouting 2>/dev/null || true - iptables -t nat -A nixos-fw-postrouting -o dsl -j MASQUERADE + ip46tables -t nat -N nixos-fw-postrouting-nat 2>/dev/null || true + iptables -t nat -A nixos-fw-postrouting-nat -o dsl -j MASQUERADE - ip46tables -t nat -A POSTROUTING -j nixos-fw-postrouting + ip46tables -t nat -A POSTROUTING -j nixos-fw-postrouting-nat - ip46tables -t mangle -D POSTROUTING -j nixos-fw-postrouting 2>/dev/null || true - ip46tables -t mangle -F nixos-fw-postrouting 2>/dev/null || true - ip46tables -t mangle -X nixos-fw-postrouting 2>/dev/null || true - ip46tables -t mangle -N nixos-fw-postrouting 2>/dev/null || true - ip46tables -A nixos-fw-postrouting -t mangle -o dsl -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu + ip46tables -t mangle -D POSTROUTING -j nixos-fw-postrouting-mangle 2>/dev/null || true + ip46tables -t mangle -F nixos-fw-postrouting-mangle 2>/dev/null || true + ip46tables -t mangle -X nixos-fw-postrouting-mangle 2>/dev/null || true - ip46tables -t mangle -A POSTROUTING -j nixos-fw-postrouting + ip46tables -t mangle -N nixos-fw-postrouting-mangle 2>/dev/null || true + ip46tables -t mangle -A nixos-fw-postrouting-mangle -o dsl -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu + + ip46tables -t mangle -A POSTROUTING -j nixos-fw-postrouting-mangle ''; }; }; -- cgit v1.2.3