blob: bd20ae7e65c755e2eecb3cf9439105db366eca41 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
|
table ip ipfoo {
map x {
type ipv4_addr : ipv4_addr
}
map y {
type ipv4_addr : ipv4_addr . inet_service
elements = { 192.168.7.2 : 10.1.1.1 . 4242 }
}
map z {
type ipv4_addr . inet_service : ipv4_addr . inet_service
elements = { 192.168.7.2 . 42 : 10.1.1.1 . 4242 }
}
chain c {
type nat hook prerouting priority dstnat; policy accept;
iifname != "foobar" accept
dnat to ip daddr map @x
ip saddr 10.1.1.1 dnat to 10.2.3.4
ip saddr 10.1.1.2 tcp dport 42 dnat to 10.2.3.4:4242
meta l4proto tcp dnat to ip saddr map @y
dnat to ip saddr . tcp dport map @z
}
}
table ip6 ip6foo {
map x {
type ipv6_addr : ipv6_addr
}
map y {
type ipv6_addr : ipv6_addr . inet_service
}
map z {
type ipv6_addr . inet_service : ipv6_addr . inet_service
}
chain c {
type nat hook prerouting priority dstnat; policy accept;
iifname != "foobar" accept
dnat to ip6 daddr map @x
ip6 saddr dead::1 dnat to feed::1
ip6 saddr dead::2 tcp dport 42 dnat to [c0::1a]:4242
meta l4proto tcp dnat to ip6 saddr map @y
dnat to ip6 saddr . tcp dport map @z
}
}
table inet inetfoo {
map x4 {
type ipv4_addr : ipv4_addr
}
map y4 {
type ipv4_addr : ipv4_addr . inet_service
}
map z4 {
type ipv4_addr . inet_service : ipv4_addr . inet_service
elements = { 192.168.7.2 . 42 : 10.1.1.1 . 4242 }
}
map x6 {
type ipv6_addr : ipv6_addr
}
map y6 {
type ipv6_addr : ipv6_addr . inet_service
}
map z6 {
type ipv6_addr . inet_service : ipv6_addr . inet_service
}
chain c {
type nat hook prerouting priority dstnat; policy accept;
iifname != "foobar" accept
dnat ip to ip daddr map @x4
ip saddr 10.1.1.1 dnat ip to 10.2.3.4
ip saddr 10.1.1.2 tcp dport 42 dnat ip to 10.2.3.4:4242
meta l4proto tcp meta nfproto ipv4 dnat ip to ip saddr map @y4
meta nfproto ipv4 dnat ip to ip saddr . tcp dport map @z4
dnat ip6 to ip6 daddr map @x6
ip6 saddr dead::1 dnat ip6 to feed::1
ip6 saddr dead::2 tcp dport 42 dnat ip6 to [c0::1a]:4242
meta l4proto tcp meta nfproto ipv6 dnat ip6 to ip6 saddr map @y6
meta nfproto ipv6 dnat ip6 to ip6 saddr . tcp dport map @z6
}
}
|