firewall/nat.nft
Hugo Levy-Falk ec80954927 MAC-IP table
2019-03-12 22:06:28 +01:00

19 lines
380 B
Plaintext

#! /sbin/nft -f
table ip nat {
chain prerouting {
type nat hook prerouting priority 0;
meta iifname $if_prerezotage ip daddr != { $intranet, $comnpay, $website } tcp dport {http,https} dnat $bounce_server;
}
chain postrouting {
type nat hook postrouting priority 100
# ip saddr 10.0.0.0/8 snat to 193.48.225.3
meta oifname $if_supelec snat to 193.48.225.3
}
}