diff options
author | lassulus <lass@aidsballs.de> | 2016-04-12 15:09:08 +0200 |
---|---|---|
committer | lassulus <lass@aidsballs.de> | 2016-04-12 15:09:08 +0200 |
commit | 7023d4141044d9de656f0d52e39650466d709728 (patch) | |
tree | b4f869dbb14474d3ea42999b5b6ea232dcf74e98 /krebs | |
parent | 4d3e713198121e2c72b7f53930ec58915845d565 (diff) |
k 3 iptables: allow REDIRECT target
Diffstat (limited to 'krebs')
-rw-r--r-- | krebs/3modules/iptables.nix | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/krebs/3modules/iptables.nix b/krebs/3modules/iptables.nix index 9596229de..4b99873a1 100644 --- a/krebs/3modules/iptables.nix +++ b/krebs/3modules/iptables.nix @@ -20,6 +20,7 @@ let flatten length hasAttr + hasPrefix mkEnableOption mkOption mkIf @@ -123,7 +124,7 @@ let buildRule = tn: cn: rule: #target validation test: - assert (elem rule.target ([ "ACCEPT" "REJECT" "DROP" "QUEUE" "LOG" "RETURN" ] ++ (attrNames ts."${tn}"))); + assert (elem rule.target ([ "ACCEPT" "REJECT" "DROP" "QUEUE" "LOG" "RETURN" ] ++ (attrNames ts."${tn}"))) || hasPrefix "REDIRECT" rule.target; #predicate validation test: #maybe use iptables-test |