You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The text was updated successfully, but these errors were encountered:
kBite
changed the title
Missing -m set option when matching source _and_ destination against ipsets
Missing -m set option when matching source and destination against ipsets
Apr 29, 2021
This is because ferm keeps only one match module in output, even if specified multiple times in config, and ipset (set modules) doesn't allow multiple --match-set for a single -m set...
Description
iptables rules generated by
ferm
from it's config are missing the second-m set
option when matching source and destination against ipsetsshould be:
instead of:
How to reproduce:
ferm
ferm
The text was updated successfully, but these errors were encountered: