]> git.ipfire.org Git - thirdparty/iptables.git/commitdiff
etc: add default IPv6 table and chain definitions
authorPablo Neira Ayuso <pablo@netfilter.org>
Tue, 30 Jul 2013 18:17:44 +0000 (20:17 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Mon, 30 Dec 2013 22:50:41 +0000 (23:50 +0100)
Add definition of table and chains to the optional xtables.conf file.

Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
etc/xtables.conf

index 6aee8aa804f68b1ba31c94968138afb9cfdedc6a..7b2b8e5f1d9a4b270124394dea8a50cef92cd3f0 100644 (file)
@@ -26,8 +26,42 @@ family ipv4 {
        }
 
        table security {
-               chain INPUT hook NF_INET_LOCAL_IN prio 150
-               chain FORWARD hook NF_INET_FORWARD prio 150
-               chain OUTPUT hook NF_INET_LOCAL_OUT prio 150
+               chain INPUT hook NF_INET_LOCAL_IN prio 50
+               chain FORWARD hook NF_INET_FORWARD prio 50
+               chain OUTPUT hook NF_INET_LOCAL_OUT prio 50
+       }
+}
+
+family ipv6 {
+       table raw {
+               chain PREROUTING hook NF_INET_PRE_ROUTING prio -300
+               chain OUTPUT hook NF_INET_LOCAL_OUT prio -300
+       }
+
+       table mangle {
+               chain PREROUTING hook NF_INET_PRE_ROUTING prio -150
+               chain INPUT hook NF_INET_LOCAL_IN prio -150
+               chain FORWARD hook NF_INET_FORWARD prio -150
+               chain OUTPUT hook NF_INET_LOCAL_OUT prio -150
+               chain POSTROUTING hook NF_INET_POST_ROUTING prio -150
+       }
+
+       table filter {
+               chain INPUT hook NF_INET_LOCAL_IN prio 0
+               chain FORWARD hook NF_INET_FORWARD prio 0
+               chain OUTPUT hook NF_INET_LOCAL_OUT prio 0
+       }
+
+       table nat {
+               chain PREROUTING hook NF_INET_PRE_ROUTING prio -100
+               chain INPUT hook NF_INET_LOCAL_IN prio -100
+               chain OUTPUT hook NF_INET_LOCAL_OUT prio 100
+               chain POSTROUTING hook NF_INET_POST_ROUTING prio 100
+       }
+
+       table security {
+               chain INPUT hook NF_INET_LOCAL_IN prio 50
+               chain FORWARD hook NF_INET_FORWARD prio 50
+               chain OUTPUT hook NF_INET_LOCAL_OUT prio 50
        }
 }