nixos-module/container/upstream: put noNat.subnets4 in proper iptables chain

This commit is contained in:
Astro 2022-09-18 19:25:58 +02:00
parent c356db8bb4
commit 555026dd84

View File

@ -94,7 +94,7 @@ in
# Do not NAT our public IPv4 addresses # Do not NAT our public IPv4 addresses
${lib.concatMapStringsSep "\n" (net: ${lib.concatMapStringsSep "\n" (net:
lib.concatMapStrings (subnet: '' lib.concatMapStrings (subnet: ''
iptables -t nat -I nixos-nat-post \ iptables -t nat -I ${net}_nat \
-s ${subnet} \ -s ${subnet} \
-j RETURN -j RETURN
'') upstreamInterfaces.${net}.upstream.noNat.subnets4 or [] '') upstreamInterfaces.${net}.upstream.noNat.subnets4 or []