• Scott Kuhl's avatar
    Make nat and nft rules consistent; improve rule ordering. · bc24ed35
    Scott Kuhl authored
    First, check if TTL indicates we should ignore packet (instead of
    checking in multiple rules later). Also, nft method didn't do this at
    all. Now, nft matches the behavior of nat.
    
    Second, forward DNS traffic (we may need to intercept traffic to
    localhost if a DNS server is running on localhost).
    
    Third, ignore any local traffic packets. (Previously, we ignored local
    traffic except DNS and then had the DNS rules). The nft method didn't
    do this previously at all. It now matches the behavior of nat.
    
    Lastly, list the subnets to redirect and/or exclude. This step is left
    unchanged. Excluding the local port that we are listening on is
    redundant with the third step, but should cause no harm.
    
    In summary, this ordering simplifies the rules in nat and eliminates
    differences that previously existed between nat and nft.
    bc24ed35
Name
Last commit
Last update
..
test_firewall.py Loading commit data...
test_helpers.py Loading commit data...
test_methods_nat.py Loading commit data...
test_methods_pf.py Loading commit data...
test_methods_tproxy.py Loading commit data...
test_options.py Loading commit data...
test_sdnotify.py Loading commit data...