From e92392db91f6eb50288f33ccf63475aa7b9babdd Mon Sep 17 00:00:00 2001 From: Daniel Golle Date: Thu, 28 Apr 2016 14:25:02 +0200 Subject: [PATCH] set mark for locally generated traffic in OUTPUT chain Signed-off-by: Daniel Golle --- rules.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules.c b/rules.c index 756c78d..e20442e 100644 --- a/rules.c +++ b/rules.c @@ -270,7 +270,7 @@ append_chain(struct fw3_ipt_rule *r, struct fw3_rule *rule) { snprintf(chain, sizeof(chain), "zone_%s_notrack", rule->src.name); } - else if (rule->target == FW3_FLAG_MARK) + else if (rule->target == FW3_FLAG_MARK && (rule->_src || rule->src.any)) { snprintf(chain, sizeof(chain), "PREROUTING"); } -- 2.30.2