From 7bef07ac78b1e081285ca5f06f0eae0fbd33f6f2 Mon Sep 17 00:00:00 2001 From: Niklas Yann Wettengel Date: Sun, 10 Nov 2019 21:52:06 +0100 Subject: mark missing interfaces --- roles/configure_iptables/templates/ip6tables.rules | 3 +++ roles/configure_iptables/templates/iptables.rules | 6 ++++++ 2 files changed, 9 insertions(+) diff --git a/roles/configure_iptables/templates/ip6tables.rules b/roles/configure_iptables/templates/ip6tables.rules index ab40344..c1e5b4c 100644 --- a/roles/configure_iptables/templates/ip6tables.rules +++ b/roles/configure_iptables/templates/ip6tables.rules @@ -25,6 +25,9 @@ {% for peer in groups['uplink'] | difference([inventory_hostname]) %} -A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff {% endfor %} +{% for peer in wireguard_bb_peers %} +-A PREROUTING -i bb{{ peer.name }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff +{% endfor %} {% endif %} COMMIT *filter diff --git a/roles/configure_iptables/templates/iptables.rules b/roles/configure_iptables/templates/iptables.rules index 8e3e3c8..bd2fcf2 100644 --- a/roles/configure_iptables/templates/iptables.rules +++ b/roles/configure_iptables/templates/iptables.rules @@ -19,9 +19,15 @@ {% for peer in groups['fastd'] %} -A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -j MARK --set-xmark 0x1/0xffffffff {% endfor %} +{% for peer in groups['nat64'] %} +-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -j MARK --set-xmark 0x1/0xffffffff +{% endfor %} {% for peer in groups['uplink'] | difference([inventory_hostname]) %} -A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -j MARK --set-xmark 0x1/0xffffffff {% endfor %} +{% for peer in wireguard_bb_peers %} +-A PREROUTING -i bb{{ peer.name }} -j MARK --set-xmark 0x1/0xffffffff +{% endfor %} {% endif %} {% if 'nat64' in group_names %} {% for peer in groups['uplink'] %} -- cgit v1.2.3-54-g00ecf