Marek Marczykowski-Górecki <marmarek@invisiblethingslab.com>
CC:
Frédéric Pierret <frederic.pierret@qubes-os.org>
Hi,
as an addendum to the previous email, the problema was the fact that the
first rule to match in the qubes-firewall table, forward chain was:
iifname !="*vif" accept
By moving that to the end of the chain, the attached one is the new
trace which makes a lot more sense and increase the counters.
However, I still cannot see any traffic reaching the next hop.