Skip to content

Commit

Permalink
fix: when deny a client, delete its both src and dst connection
Browse files Browse the repository at this point in the history
Signed-off-by: Dengfeng Liu <[email protected]>
  • Loading branch information
liudf0716 committed Sep 27, 2024
1 parent d007144 commit e61f075
Showing 1 changed file with 5 additions and 4 deletions.
9 changes: 5 additions & 4 deletions src/fw4_nft.c
Original file line number Diff line number Diff line change
Expand Up @@ -101,6 +101,7 @@ const char *nft_wifidogx_init_script[] = {
"add rule inet fw4 forward_wifidogx_wan meta mark 0x10000 accept",
"add rule inet fw4 forward_wifidogx_wan meta mark 0x20000 accept",
"add rule inet fw4 forward_wifidogx_wan jump forward_wifidogx_unknown",
"add rule inet fw4 forward_wifidogx_unkown jump handle_reject",
"add rule inet fw4 forward_wifidogx_auth_servers ip daddr @set_wifidogx_auth_servers accept",
"add rule inet fw4 forward_wifidogx_auth_servers ip6 daddr @set_wifidogx_auth_servers_v6 accept",
"add rule inet fw4 forward_wifidogx_trust_domains ip daddr @set_wifidogx_trust_domains accept",
Expand All @@ -111,13 +112,13 @@ const char *nft_wifidogx_init_script[] = {
};

const char *nft_wifidogx_dhcp_pass_script[] = {
"add rule inet fw4 forward_wifidogx_unknown udp dport 67 accept",
"add rule inet fw4 forward_wifidogx_unknown tcp dport 67 accept",
"insert rule inet fw4 forward_wifidogx_unknown udp dport 67 accept",
"insert rule inet fw4 forward_wifidogx_unknown tcp dport 67 accept",
};

const char *nft_wifidogx_dns_pass_script[] = {
"add rule inet fw4 forward_wifidogx_unknown udp dport 53 accept",
"add rule inet fw4 forward_wifidogx_unknown tcp dport 53 accept",
"insert rule inet fw4 forward_wifidogx_unknown udp dport 53 accept",
"insert rule inet fw4 forward_wifidogx_unknown tcp dport 53 accept",
};

const char *nft_wifidogx_dhcp_redirect_script[] = {
Expand Down

0 comments on commit e61f075

Please sign in to comment.