upstream4: turn nat reflection back on for vpn-gw:wireguard
SNAT is needed as vpn-gw's default route does not go over upstream4.
This commit is contained in:
parent
848cf110ed
commit
90a9ece874
|
@ -173,6 +173,7 @@ in
|
||||||
destination = config.site.net.core.hosts4.vpn-gw;
|
destination = config.site.net.core.hosts4.vpn-gw;
|
||||||
proto = "udp";
|
proto = "udp";
|
||||||
sourcePort = config.site.vpn.wireguard.port;
|
sourcePort = config.site.vpn.wireguard.port;
|
||||||
|
reflect = true;
|
||||||
}
|
}
|
||||||
{
|
{
|
||||||
destination = servHosts.gnunet;
|
destination = servHosts.gnunet;
|
||||||
|
|
Loading…
Reference in New Issue
Block a user