|
|
@ -14,6 +14,9 @@
|
|
|
|
{% for peer in groups['ffrl_uplink'] %}
|
|
|
|
{% for peer in groups['ffrl_uplink'] %}
|
|
|
|
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff
|
|
|
|
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff
|
|
|
|
{% endfor %}
|
|
|
|
{% endfor %}
|
|
|
|
|
|
|
|
{% for peer in groups['mullvad_uplink'] %}
|
|
|
|
|
|
|
|
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff
|
|
|
|
|
|
|
|
{% endfor %}
|
|
|
|
{% endif %}
|
|
|
|
{% endif %}
|
|
|
|
{% if 'mullvad_uplink' in group_names %}
|
|
|
|
{% if 'mullvad_uplink' in group_names %}
|
|
|
|
{% for peer in groups['fastd'] %}
|
|
|
|
{% for peer in groups['fastd'] %}
|
|
|
@ -55,16 +58,23 @@ COMMIT
|
|
|
|
{% if 'fastd' in group_names %}
|
|
|
|
{% if 'fastd' in group_names %}
|
|
|
|
{% for peer in groups['ffrl_uplink'] %}
|
|
|
|
{% for peer in groups['ffrl_uplink'] %}
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
|
|
|
|
-A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT
|
|
|
|
|
|
|
|
{% endfor %}
|
|
|
|
|
|
|
|
{% for peer in groups['mullvad_uplink'] %}
|
|
|
|
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
|
|
|
|
-A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT
|
|
|
|
{% endfor %}
|
|
|
|
{% endfor %}
|
|
|
|
{% endif %}
|
|
|
|
{% endif %}
|
|
|
|
{% if 'mullvad_uplink' in group_names %}
|
|
|
|
{% if 'mullvad_uplink' in group_names %}
|
|
|
|
{% for peer in groups['fastd'] %}
|
|
|
|
{% for peer in groups['fastd'] %}
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
|
|
|
|
-A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT
|
|
|
|
{% endfor %}
|
|
|
|
{% endfor %}
|
|
|
|
{% endif %}
|
|
|
|
{% endif %}
|
|
|
|
{% if 'ffrl_uplink' in group_names %}
|
|
|
|
{% if 'ffrl_uplink' in group_names %}
|
|
|
|
{% for peer in groups['fastd'] %}
|
|
|
|
{% for peer in groups['fastd'] %}
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
|
|
|
|
-A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT
|
|
|
|
{% endfor %}
|
|
|
|
{% endfor %}
|
|
|
|
{% endif %}
|
|
|
|
{% endif %}
|
|
|
|
# MOSH
|
|
|
|
# MOSH
|
|
|
|