Browse Source

nftables: Allow link-local IPv6 in uRPF check

Signed-off-by: Maximilian Wilhelm <max@sdn.clinic>
Maximilian Wilhelm 3 years ago
parent
commit
e2a4779460
1 changed files with 1 additions and 0 deletions
  1. 1 0
      nftables/nftables.conf.tmpl

+ 1 - 0
nftables/nftables.conf.tmpl

@@ -236,6 +236,7 @@ table ip6 filter {
 	}
 
 	chain urpf {
+		ip6 saddr fe80::/64 return
 {%- for iface_cfg in urpf  %}
   {%- for pfx in iface_cfg[6] %}
 		iif {{ iface_cfg['iface'] }} ip6 saddr {{ pfx }} return