forked from freifunk-franken/firmware
Fabian Bläse
157fa4eac5
Include nftables and appropriate modules. Translate ip- and ebtables rules to their nftables counterparts. Remove ip/ebtables and modules. This change intentionally tries to keep structural changes at a minimum to keep the rule translation comprehensible. kmod-nft-bridge is not required for fff-node, because it was merged into a single kernel module since Linux 4.17: [1]02c7b25e5f
[2]fbaf48387e
Fixes: #252 Signed-off-by: Fabian Bläse <fabian@blaese.de> Co-authored-by: Johannes Kimmel <fff@bareminimum.eu>
14 lines
347 B
Plaintext
14 lines
347 B
Plaintext
nft -f - <<__EOF
|
|
table bridge filter {
|
|
chain MULTICAST_OUT {
|
|
# Erlaube alles was nicht IP ?? ist " hop-by-hop " ??
|
|
# -p IPv6 --ip6-proto ip -j RETURN
|
|
ether type ip6 ip6 nexthdr 0 counter return
|
|
|
|
# Erlaube Organisation der Multicast Gruppen
|
|
# -p IPv4 --ip-proto igmp -j RETURN
|
|
ether type ip meta l4proto igmp counter return
|
|
}
|
|
}
|
|
__EOF
|