diff options
Diffstat (limited to 'modules')
| -rw-r--r-- | modules/router.nix | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/modules/router.nix b/modules/router.nix index 63b39fb..53d14fd 100644 --- a/modules/router.nix +++ b/modules/router.nix @@ -295,8 +295,8 @@ ip protocol icmp limit rate 4/second counter accept comment "icmp v4" ip6 nexthdr ipv6-icmp limit rate 4/second counter accept comment "accept all ICMP types" ct state vmap { established : accept, related : accept, invalid : drop } - - jump miniupnpd + # For miniupnpd. + ct status dnat accept # Don't allow accidental vpn forwarding to wan. iifname vpnlan-vport oifname wan-vport counter reject |
