X-Git-Url: https://git.distorted.org.uk/~mdw/firewall/blobdiff_plain/a92589b82be0e9123e7f782734ecee64c06fcf3d..d052f3435f85d5b61ace87e158f77b7f37080395:/radius.m4 diff --git a/radius.m4 b/radius.m4 index b8481bb..090249c 100644 --- a/radius.m4 +++ b/radius.m4 @@ -57,6 +57,12 @@ iptables -A fwd-spec-nofrag -j ACCEPT \ -m mark --mark $from_untrusted/$MASK_FROM \ -m state --state ESTABLISHED +## BCP38 filtering. Note that addresses here are seen before NAT is applied. +bcp38 4 ppp0 62.49.204.144/28 172.29.198.0/23 +bcp38 6 t6-he \ + 2001:470:1f08:1b98::2 2001:470:1f09:1b98::/64 \ + 2001:470:9740::/48 + ## NAT for RFC1918 addresses. for i in PREROUTING OUTPUT POSTROUTING; do run iptables -t nat -P $i ACCEPT 2>/dev/null || :