From 459b6932412334feafd63bb9dfcdf16d8acd8d61 Mon Sep 17 00:00:00 2001 From: Florian Westphal Date: Sat, 27 Jan 2018 11:09:46 +0100 Subject: policy: add nft translation for simple policy none/strict use case Signed-off-by: Florian Westphal Signed-off-by: Pablo Neira Ayuso --- extensions/libxt_policy.txlate | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 extensions/libxt_policy.txlate (limited to 'extensions/libxt_policy.txlate') diff --git a/extensions/libxt_policy.txlate b/extensions/libxt_policy.txlate new file mode 100644 index 00000000..66788a76 --- /dev/null +++ b/extensions/libxt_policy.txlate @@ -0,0 +1,5 @@ +iptables-translate -A INPUT -m policy --pol ipsec --dir in +nft add rule ip filter INPUT meta secpath exists counter + +iptables-translate -A INPUT -m policy --pol none --dir in +nft add rule ip filter INPUT meta secpath missing counter -- cgit v1.2.3