Browse Source

nftables: respondd needs to be allowed on all B.A.T.M.A.N. adv. nodes

Signed-off-by: Maximilian Wilhelm <max@sdn.clinic>
Maximilian Wilhelm 3 years ago
parent
commit
c221f2d6e7
1 changed files with 2 additions and 2 deletions
  1. 2 2
      _modules/ffho_netfilter.py

+ 2 - 2
_modules/ffho_netfilter.py

@@ -137,8 +137,8 @@ def generate_service_rules (fw_config, node_config):
 	if _allow_dhcp (fw_policy, roles):
 		rules[4].append ('udp dport 67 counter accept comment "DHCP"')
 
-	# Allow respondd queries on gateways
-	if 'batman_gw' in roles:
+	# Allow respondd queries on B.A.T.M.A.N. adv. nodes
+	if 'batman' in roles:
 		rules[6].append ('ip6 saddr fe80::/64 ip6 daddr ff05::2:1001 udp dport 1001 counter accept comment "responnd"')
 
 	for af in [ 4, 6 ]: