diff --git a/nftables.patch b/nftables.patch index 7c93761..ca3f40f 100644 --- a/nftables.patch +++ b/nftables.patch @@ -54,8 +54,8 @@ chain prerouting { type nat hook prerouting priority dstnat; policy accept; # Uncomment for E2Guardian -- # iifname $LAN ip daddr != 192.168.1.0/24 tcp dport 80 redirect to :8080 -- # iifname $LAN ip daddr != 192.168.1.0/24 tcp dport 443 redirect to :8443 +- iifname $LAN ip daddr != 192.168.1.0/24 tcp dport 80 redirect to :8080 +- iifname $LAN ip daddr != 192.168.1.0/24 tcp dport 443 redirect to :8443 + iifname $LAN ip daddr != $LANRANGE ip daddr != @blocklist tcp dport 80 redirect to :8080 + iifname $LAN ip daddr != $LANRANGE ip daddr != @blocklist tcp dport 443 redirect to :8443 }