mirror of
https://github.com/TeaOSLab/EdgeNode.git
synced 2025-11-08 03:00:27 +08:00
创建nftables规则时,使用REJECT代替DROP
This commit is contained in:
@@ -235,13 +235,13 @@ func (this *NFTablesFirewall) init() error {
|
|||||||
if setAction == "allow" {
|
if setAction == "allow" {
|
||||||
rule, err = chain.AddAcceptIPv4SetRule(setName, ruleName)
|
rule, err = chain.AddAcceptIPv4SetRule(setName, ruleName)
|
||||||
} else {
|
} else {
|
||||||
rule, err = chain.AddDropIPv4SetRule(setName, ruleName)
|
rule, err = chain.AddRejectIPv4SetRule(setName, ruleName)
|
||||||
}
|
}
|
||||||
} else if tableDef.IsIPv6 {
|
} else if tableDef.IsIPv6 {
|
||||||
if setAction == "allow" {
|
if setAction == "allow" {
|
||||||
rule, err = chain.AddAcceptIPv6SetRule(setName, ruleName)
|
rule, err = chain.AddAcceptIPv6SetRule(setName, ruleName)
|
||||||
} else {
|
} else {
|
||||||
rule, err = chain.AddDropIPv6SetRule(setName, ruleName)
|
rule, err = chain.AddRejectIPv6SetRule(setName, ruleName)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|||||||
Reference in New Issue
Block a user