upstream: fix masquerading
This commit is contained in:
parent
a2f7356c53
commit
8bc945244d
|
@ -103,7 +103,17 @@ in
|
|||
-d ${staticIpv4Address} -p ${fwd.proto} \
|
||||
--dport ${builtins.toString fwd.sourcePort} \
|
||||
-j DNAT --to-destination ${fwd.destination}
|
||||
'') config.networking.nat.forwardPorts}
|
||||
|
||||
iptables -t nat -A nixos-nat-post \
|
||||
-d ${fwd.destination} -p ${fwd.proto} \
|
||||
--dport ${builtins.toString fwd.destination} \
|
||||
-s ${config.site.net.core.subnets4} -j MASQUERADE
|
||||
|
||||
iptables -t nat -A nixos-nat-post \
|
||||
-d ${fwd.destination} -p ${fwd.proto} \
|
||||
--dport ${builtins.toString fwd.destination} \
|
||||
-s ${config.site.net.c3d2.subnets4} -j MASQUERADE
|
||||
'') config.networking.nat.forwardPorts}
|
||||
''}
|
||||
|
||||
# Do not NAT our public IPv4 addresses
|
||||
|
|
Loading…
Reference in New Issue