Compile conntrack rules into raw-priority chains
This commit is contained in:
@@ -69,6 +69,22 @@ func (e *Engine) ensureChains(table *nftables.Table, policies map[string]nftable
|
||||
Hooknum: nftables.ChainHookPrerouting,
|
||||
Priority: nftables.ChainPriorityNATDest,
|
||||
},
|
||||
"raw_prerouting": {
|
||||
Name: "raw_prerouting",
|
||||
Table: table,
|
||||
Type: nftables.ChainTypeFilter,
|
||||
Hooknum: nftables.ChainHookPrerouting,
|
||||
Priority: nftables.ChainPriorityRaw,
|
||||
Policy: policyPtr(nftables.ChainPolicyAccept),
|
||||
},
|
||||
"raw_output": {
|
||||
Name: "raw_output",
|
||||
Table: table,
|
||||
Type: nftables.ChainTypeFilter,
|
||||
Hooknum: nftables.ChainHookOutput,
|
||||
Priority: nftables.ChainPriorityRaw,
|
||||
Policy: policyPtr(nftables.ChainPolicyAccept),
|
||||
},
|
||||
}
|
||||
|
||||
for name, chain := range chains {
|
||||
|
||||
Reference in New Issue
Block a user