nixos-module/container/upstream: allow smtp from flpk too
This commit is contained in:
parent
5a3194b23c
commit
a1f2e2a1d6
|
@ -77,6 +77,7 @@ in
|
||||||
iptables -N fwd_smtp || \
|
iptables -N fwd_smtp || \
|
||||||
iptables -F fwd_smtp
|
iptables -F fwd_smtp
|
||||||
iptables -A fwd_smtp --source ${config.site.net.serv.subnet4} -j RETURN
|
iptables -A fwd_smtp --source ${config.site.net.serv.subnet4} -j RETURN
|
||||||
|
iptables -A fwd_smtp --source ${config.site.net.flpk.subnet4} -j RETURN
|
||||||
iptables -A fwd_smtp -j REJECT
|
iptables -A fwd_smtp -j REJECT
|
||||||
iptables -I FORWARD -p tcp --dport 25 -j fwd_smtp
|
iptables -I FORWARD -p tcp --dport 25 -j fwd_smtp
|
||||||
|
|
||||||
|
@ -85,7 +86,10 @@ in
|
||||||
${lib.concatMapStrings (subnet6: ''
|
${lib.concatMapStrings (subnet6: ''
|
||||||
ip6tables -A fwd_smtp --source ${subnet6} -j RETURN
|
ip6tables -A fwd_smtp --source ${subnet6} -j RETURN
|
||||||
ip6tables -A fwd_smtp --dest ${subnet6} -j RETURN
|
ip6tables -A fwd_smtp --dest ${subnet6} -j RETURN
|
||||||
'') (builtins.attrValues config.site.net.serv.subnets6)}
|
'') (builtins.concatMap builtins.attrValues [
|
||||||
|
config.site.net.serv.subnets6
|
||||||
|
config.site.net.flpk.subnets6
|
||||||
|
])}
|
||||||
ip6tables -A fwd_smtp -j REJECT
|
ip6tables -A fwd_smtp -j REJECT
|
||||||
ip6tables -I FORWARD -p tcp --dport 25 -j fwd_smtp
|
ip6tables -I FORWARD -p tcp --dport 25 -j fwd_smtp
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue