Skip to content

Commit

Permalink
fix: ip rule is not added when only binding to wan (#399)
Browse files Browse the repository at this point in the history
  • Loading branch information
mzz2017 authored Jan 2, 2024
1 parent 9aa9b69 commit d1d0f6d
Show file tree
Hide file tree
Showing 3 changed files with 10 additions and 4 deletions.
9 changes: 6 additions & 3 deletions control/control_plane.go
Original file line number Diff line number Diff line change
Expand Up @@ -194,12 +194,15 @@ func NewControlPlane(
}
}()

/// Bind to links. Binding should be advance of dialerGroups to avoid un-routable old connection.
// Bind to LAN
if len(global.LanInterface) > 0 {
if len(global.LanInterface) > 0 || len(global.WanInterface) > 0 {
if err = core.setupRoutingPolicy(); err != nil {
return nil, err
}
}

/// Bind to links. Binding should be advance of dialerGroups to avoid un-routable old connection.
// Bind to LAN
if len(global.LanInterface) > 0 {
if global.AutoConfigKernelParameter {
_ = SetIpv4forward("1")
}
Expand Down
2 changes: 1 addition & 1 deletion docs/en/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -195,7 +195,7 @@ group {

# See https://github.com/daeuniverse/dae/blob/main/docs/en/configuration/routing.md for full examples.
routing {
pname(NetworkManager) -> direct
pname(NetworkManager, systemd-resolved, dnsmasq) -> must_direct
dip(224.0.0.0/3, 'ff00::/8') -> direct

### Write your rules below.
Expand Down
3 changes: 3 additions & 0 deletions example.dae
Original file line number Diff line number Diff line change
Expand Up @@ -202,6 +202,9 @@ routing {
# WAN.
pname(NetworkManager) -> direct

# Bypass DNS stubs. We want to bypass their DNS requests, thus use 'must'.
pname(systemd-resolved, dnsmasq) -> must_direct

# Put it in the front to prevent broadcast, multicast and other packets that should be sent to the LAN from being
# forwarded by the proxy.
# "dip" means destination IP.
Expand Down

0 comments on commit d1d0f6d

Please sign in to comment.