use RETURN instead ACCEPT for tap-out rules
authorAlexandre Derumier <aderumier@odiso.com>
Tue, 25 Feb 2014 12:24:06 +0000 (13:24 +0100)
committerDietmar Maurer <dietmar@proxmox.com>
Tue, 25 Feb 2014 12:36:26 +0000 (13:36 +0100)
Signed-off-by: Alexandre Derumier <aderumier@odiso.com>
PVE/Firewall.pm

index a19505a..ea24cfb 100644 (file)
@@ -684,10 +684,10 @@ sub generate_tap_rules_direction {
                    generate_group_rules($ruleset, $group_rules, $2);
                }
                ruleset_generate_rule($ruleset, $tapchain, $rule);
-               ruleset_addrule($ruleset, $tapchain, "-m mark --mark 1 -g $bridge-IN")
+               ruleset_addrule($ruleset, $tapchain, "-m mark --mark 1 -j RETURN")
                    if $direction eq 'OUT';
            } else {
-               $rule->{action} = "$bridge-IN" if $rule->{action} eq 'ACCEPT' && $direction eq 'OUT';
+               $rule->{action} = "RETURN" if $rule->{action} eq 'ACCEPT' && $direction eq 'OUT';
                ruleset_generate_rule($ruleset, $tapchain, $rule);
            }
        }