Commit d2e2fdf0 authored by Kaarle Ritvanen's avatar Kaarle Ritvanen

support for REDIRECT target

parent 946e90f2
......@@ -46,8 +46,12 @@ function NATRule:chain() return self.params.chain end
function NATRule:target()
if self.action then return end
if not self['ip-range'] then self:error('IP range not defined for NAT rule') end
local target =' --to-'..self.params.subject..' '..self['ip-range']
local target
if self['ip-range'] then
target =' --to-'..self.params.subject..' '..self['ip-range']
else target = self.params.deftarget end
if self['port-range'] then target = target..':'..self['port-range'] end
return target
......@@ -58,7 +62,7 @@ local DNATRule = model.class(NATRule)
function DNATRule:init(...)
NATRule.init(self, unpack(arg))
self.params = {forbidif='out', subject='destination',
chain='PREROUTING', target='DNAT'}
chain='PREROUTING', target='DNAT', deftarget='REDIRECT'}
......@@ -67,12 +71,7 @@ local SNATRule = model.class(NATRule)
function SNATRule:init(...)
NATRule.init(self, unpack(arg))
self.params = {forbidif='in', subject='source',
chain='POSTROUTING', target='SNAT'}
function SNATRule:target()
if self.action or self['ip-range'] then return end
return 'MASQUERADE'..(self['port-range'] and ' --to-ports '..self['port-range'] or '')
chain='POSTROUTING', target='SNAT', deftarget='MASQUERADE'}
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment