vm/network: really place anti-spoof rules in 'raw' table
This fixes commit: 4d68998 vm/network: place anti-spoof rules in 'raw' table
This commit is contained in:
		
							parent
							
								
									a2afb6e054
								
							
						
					
					
						commit
						8a7906a016
					
				@ -48,7 +48,7 @@ if [ "${ip}" ] ; then
 | 
			
		||||
		${cmdprefix} ip route ${ipcmd} ${addr} dev ${vif} || true
 | 
			
		||||
	done
 | 
			
		||||
		echo ${cmdprefix} iptables -t raw $iptables_cmd -i ${vif} \! -s ${ip} -j DROP
 | 
			
		||||
		${cmdprefix} iptables $iptables_cmd -i ${vif} \! -s ${ip} -j DROP
 | 
			
		||||
		${cmdprefix} iptables -t raw $iptables_cmd -i ${vif} \! -s ${ip} -j DROP
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
log debug "Successful vif-route-qubes $command for $vif."
 | 
			
		||||
 | 
			
		||||
		Loading…
	
		Reference in New Issue
	
	Block a user