vm/network: really place anti-spoof rules in 'raw' table
This fixes commit:
4d68998 vm/network: place anti-spoof rules in 'raw' table
			
			
This commit is contained in:
		
							parent
							
								
									1d5f54c976
								
							
						
					
					
						commit
						4d0839d05b
					
				| @ -48,7 +48,7 @@ if [ "${ip}" ] ; then | |||||||
| 		${cmdprefix} ip route ${ipcmd} ${addr} dev ${vif} || true | 		${cmdprefix} ip route ${ipcmd} ${addr} dev ${vif} || true | ||||||
| 	done | 	done | ||||||
| 		echo ${cmdprefix} iptables -t raw $iptables_cmd -i ${vif} \! -s ${ip} -j DROP | 		echo ${cmdprefix} iptables -t raw $iptables_cmd -i ${vif} \! -s ${ip} -j DROP | ||||||
| 		${cmdprefix} iptables $iptables_cmd -i ${vif} \! -s ${ip} -j DROP | 		${cmdprefix} iptables -t raw $iptables_cmd -i ${vif} \! -s ${ip} -j DROP | ||||||
| fi | fi | ||||||
| 
 | 
 | ||||||
| log debug "Successful vif-route-qubes $command for $vif." | log debug "Successful vif-route-qubes $command for $vif." | ||||||
|  | |||||||
		Loading…
	
		Reference in New Issue
	
	Block a user
	 Marek Marczykowski
						Marek Marczykowski