nat: exclude lo from masquerade

This commit is contained in:
Grigory Shipunov 2023-02-08 16:38:58 +01:00
parent d638a73d3e
commit 0c63cfbe7a
Signed by: 0xa
GPG key ID: 91FA5E5BF9AA901C

View file

@ -13,7 +13,7 @@
# port-forward ssh to the music machine
extraCommands = ''
iptables -t nat -I PREROUTING -p tcp --dport 2020 -j DNAT --to-destination 10.34.45.101:22
iptables -t nat -A POSTROUTING -j MASQUERADE
iptables ! -o lo -t nat -A POSTROUTING -j MASQUERADE
'';
extraStopCommands = ''
iptables -t nat -D PREROUTING -p tcp --dport 2020 -j DNAT --to-destination 10.34.45.101:22 || true