mirror of
https://github.com/dangeroustech/ZeroTierBridge.git
synced 2025-12-06 00:56:58 +00:00
fix: allow bi-directional traffic initiation
This commit is contained in:
@@ -7,8 +7,8 @@ services:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
args:
|
||||
ARCH: arm64
|
||||
VERSION: 1.6.5
|
||||
ARCH: amd64
|
||||
VERSION: 1.6.6
|
||||
restart: always
|
||||
privileged: true
|
||||
volumes:
|
||||
|
||||
@@ -31,11 +31,12 @@ do
|
||||
|
||||
if [ "$ZT_BRIDGE" = "true" ]
|
||||
then
|
||||
echo "iptables on $(zerotier-cli get $n portDeviceName)"
|
||||
echo "Configuring iptables on $(zerotier-cli get $n portDeviceName)"
|
||||
PHY_IFACE=eth0; ZT_IFACE=$(zerotier-cli get $n portDeviceName)
|
||||
|
||||
iptables -t nat -A POSTROUTING -o $PHY_IFACE -j MASQUERADE
|
||||
iptables -A FORWARD -i $PHY_IFACE -o $ZT_IFACE -m state --state RELATED,ESTABLISHED -j ACCEPT
|
||||
iptables -t nat -A POSTROUTING -o $ZT_IFACE -j MASQUERADE
|
||||
iptables -A FORWARD -i $PHY_IFACE -o $ZT_IFACE -j ACCEPT
|
||||
iptables -A FORWARD -i $ZT_IFACE -o $PHY_IFACE -j ACCEPT
|
||||
fi
|
||||
done
|
||||
|
||||
Reference in New Issue
Block a user