Merge branch 'Fenlly-reverse-nft-rule-checking'

This commit is contained in:
Andrew David Wong 2018-06-04 20:08:05 -05:00
commit 4d44378674
No known key found for this signature in database
GPG Key ID: 8CE137352A019A17

View File

@ -384,7 +384,7 @@ fi
# In Qubes OS R4
# If not already present
if nft -nn list table ip qubes-firewall | grep "tcp dport 443 ct state new"; then
if ! nft -nn list table ip qubes-firewall | grep "tcp dport 443 ct state new"; then
# Add a filtering rule
nft add rule ip qubes-firewall forward meta iifname eth0 ip saddr 192.168.x.0/24 ip daddr 10.137.0.y tcp dport 443 ct state new counter accept