summaryrefslogtreecommitdiff
path: root/data/templates/nat/iptables-restore.tmpl
diff options
context:
space:
mode:
authorChristian Poessinger <christian@poessinger.com>2020-05-01 19:25:36 +0200
committerChristian Poessinger <christian@poessinger.com>2020-05-16 15:30:26 +0200
commita927192af24079e6d392e5cae0340441490c0091 (patch)
tree72d48944264f05a6dc85364aa8fd53fe95c6ceb8 /data/templates/nat/iptables-restore.tmpl
parenta5650abb6d575de2f696a934d52468992ac9f1e9 (diff)
downloadvyos-1x-a927192af24079e6d392e5cae0340441490c0091.tar.gz
vyos-1x-a927192af24079e6d392e5cae0340441490c0091.zip
nat: T2198: move from iptables to nftables
Diffstat (limited to 'data/templates/nat/iptables-restore.tmpl')
-rw-r--r--data/templates/nat/iptables-restore.tmpl38
1 files changed, 0 insertions, 38 deletions
diff --git a/data/templates/nat/iptables-restore.tmpl b/data/templates/nat/iptables-restore.tmpl
deleted file mode 100644
index f20a05719..000000000
--- a/data/templates/nat/iptables-restore.tmpl
+++ /dev/null
@@ -1,38 +0,0 @@
-### Autogenerated by nat.py ###
-
-*nat
-:PREROUTING ACCEPT [0:0]
-:INPUT ACCEPT [0:0]
-:OUTPUT ACCEPT [0:0]
-:POSTROUTING ACCEPT [0:0]
-:VYATTA_PRE_DNAT_HOOK - [0:0]
-:VYATTA_PRE_SNAT_HOOK - [0:0]
--A PREROUTING -j VYATTA_PRE_DNAT_HOOK
-{% for r in destination -%}
-{% if (',' in r.dest_port) or ('-' in r.dest_port) %}
-
-{% if r.protocol == 'tcp_udp' %}
-# protocol has been tcp_udp - create two distinct rules
--A PREROUTING -i {{ r.interface_in }} -p tcp -m multiport --dports {{ r.dest_port | replace('-', ':') }} -m comment --comment "DST-NAT-{{ r.number }} tcp_udp" -j DNAT --to-destination {{ r.translation_address }}{{ ":" + r.translation_port if r.translation_port }}
--A PREROUTING -i {{ r.interface_in }} -p udp -m multiport --dports {{ r.dest_port | replace('-', ':') }} -m comment --comment "DST-NAT-{{ r.number }} tcp_udp" -j DNAT --to-destination {{ r.translation_address }}{{ ":" + r.translation_port if r.translation_port }}
-{% else %}
--A PREROUTING -i {{ r.interface_in }} -p {{ r.protocol }} -m multiport --dports {{ r.dest_port | replace('-', ':') }} -m comment --comment DST-NAT-{{ r.number }} -j DNAT --to-destination {{ r.translation_address }}{{ ":" + r.translation_port if r.translation_port }}
-{%- endif %}
-
-{% else %}
-
-{% if r.protocol == 'tcp_udp' %}
-# protocol has been tcp_udp - create two distinct rules
--A PREROUTING -i {{ r.interface_in }} -p tcp -m {{ r.protocol }} --dports {{ r.dest_port }} -m comment --comment "DST-NAT-{{ r.number }} tcp_udp" -j DNAT --to-destination {{ r.translation_address }}{{ ":" + r.translation_port if r.translation_port }}
--A PREROUTING -i {{ r.interface_in }} -p udp -m {{ r.protocol }} --dports {{ r.dest_port }} -m comment --comment "DST-NAT-{{ r.number }} tcp_udp" -j DNAT --to-destination {{ r.translation_address }}{{ ":" + r.translation_port if r.translation_port }}
-{% else %}
--A PREROUTING -i {{ r.interface_in }} -p {{ r.protocol }} -m {{ r.protocol }} --dport {{ r.dest_port }} -m comment --comment DST-NAT-{{ r.number }} -j DNAT --to-destination {{ r.translation_address }}{{ ":" + r.translation_port if r.translation_port }}
-{% endif %}
-
-{%- endif %}
-
-{% endfor %}
--A POSTROUTING -j VYATTA_PRE_SNAT_HOOK
--A VYATTA_PRE_DNAT_HOOK -j RETURN
--A VYATTA_PRE_SNAT_HOOK -j RETURN
-COMMIT