summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorNiklas Yann Wettengel <niyawe@niyawe.de>2019-11-10 21:52:06 +0100
committerNiklas Yann Wettengel <niyawe@niyawe.de>2019-11-10 21:52:06 +0100
commit7bef07ac78b1e081285ca5f06f0eae0fbd33f6f2 (patch)
treea7b989fbe853e196d19e1da289756643940ced24
parent9670cc8980e479e25169ba519f0e5f3f23e0fbfa (diff)
mark missing interfaces
-rw-r--r--roles/configure_iptables/templates/ip6tables.rules3
-rw-r--r--roles/configure_iptables/templates/iptables.rules6
2 files changed, 9 insertions, 0 deletions
diff --git a/roles/configure_iptables/templates/ip6tables.rules b/roles/configure_iptables/templates/ip6tables.rules
index ab40344..c1e5b4c 100644
--- a/roles/configure_iptables/templates/ip6tables.rules
+++ b/roles/configure_iptables/templates/ip6tables.rules
@@ -25,6 +25,9 @@
{% for peer in groups['uplink'] | difference([inventory_hostname]) %}
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff
{% endfor %}
+{% for peer in wireguard_bb_peers %}
+-A PREROUTING -i bb{{ peer.name }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff
+{% endfor %}
{% endif %}
COMMIT
*filter
diff --git a/roles/configure_iptables/templates/iptables.rules b/roles/configure_iptables/templates/iptables.rules
index 8e3e3c8..bd2fcf2 100644
--- a/roles/configure_iptables/templates/iptables.rules
+++ b/roles/configure_iptables/templates/iptables.rules
@@ -19,9 +19,15 @@
{% for peer in groups['fastd'] %}
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -j MARK --set-xmark 0x1/0xffffffff
{% endfor %}
+{% for peer in groups['nat64'] %}
+-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -j MARK --set-xmark 0x1/0xffffffff
+{% endfor %}
{% for peer in groups['uplink'] | difference([inventory_hostname]) %}
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -j MARK --set-xmark 0x1/0xffffffff
{% endfor %}
+{% for peer in wireguard_bb_peers %}
+-A PREROUTING -i bb{{ peer.name }} -j MARK --set-xmark 0x1/0xffffffff
+{% endfor %}
{% endif %}
{% if 'nat64' in group_names %}
{% for peer in groups['uplink'] %}