ruleset_create_chain($ruleset, "PVEFW-FWBR-IN");
ruleset_chain_add_input_filters($ruleset, "PVEFW-FWBR-IN", $hostfw_options);
- ruleset_addrule($ruleset, "PVEFW-FORWARD", "-m physdev --physdev-is-bridged --physdev-in link+ -j PVEFW-FWBR-IN");
+ ruleset_addrule($ruleset, "PVEFW-FORWARD", "-m physdev --physdev-is-bridged --physdev-in fwln+ -j PVEFW-FWBR-IN");
ruleset_create_chain($ruleset, "PVEFW-FWBR-OUT");
- ruleset_addrule($ruleset, "PVEFW-FORWARD", "-m physdev --physdev-is-bridged --physdev-out link+ -j PVEFW-FWBR-OUT");
+ ruleset_addrule($ruleset, "PVEFW-FORWARD", "-m physdev --physdev-is-bridged --physdev-out fwln+ -j PVEFW-FWBR-OUT");
ruleset_create_chain($ruleset, "PVEFW-VENET-IN");
ruleset_chain_add_input_filters($ruleset, "PVEFW-VENET-IN", $hostfw_options);
$pkg->{mac_source} = $macaddr;
my $brpkg = copy_packet($pkg);
$brpkg->{physdev_in} = "tap${vmid}i0";
- $brpkg->{physdev_out} = "link${vmid}i0";
+ $brpkg->{physdev_out} = "fwln${vmid}i0";
$brpkg->{iface_in} = $brpkg->{iface_out} = "fwbr${vmid}i0";
$pre_test = ['PVEFW-FORWARD', $brpkg];
} else {
$pkg->{iface_out} = $net->{bridge} || die "unable to get bridge";
my $brpkg = copy_packet($pkg);
$brpkg->{physdev_out} = "tap${vmid}i0";
- $brpkg->{physdev_in} = "link${vmid}i0";
+ $brpkg->{physdev_in} = "fwln${vmid}i0";
$brpkg->{iface_in} = $brpkg->{iface_out} = "fwbr${vmid}i0";
$post_test = ['PVEFW-FORWARD', $brpkg];
} else {