rules.v6.j2 437 B

1234567891011121314151617
  1. # Generated by Ansible
  2. *mangle
  3. :PREROUTING ACCEPT [0:0]
  4. :INPUT ACCEPT [0:0]
  5. :FORWARD ACCEPT [0:0]
  6. :OUTPUT ACCEPT [0:0]
  7. :POSTROUTING ACCEPT [0:0]
  8. # MSS clamping
  9. {% if peers is defined %}{%for peer in peers %}
  10. -A POSTROUTING -o {{ peer.name }} -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss ! --mss 0:1220 -j TCPMSS --set-mss 1220
  11. {%endfor%}{% endif %}
  12. COMMIT
  13. *filter
  14. :INPUT ACCEPT [0:0]
  15. :FORWARD ACCEPT [0:0]
  16. :OUTPUT ACCEPT [0:0]
  17. COMMIT