From 63668fc84ec2c51c4061bffe8db621ec053a45ad Mon Sep 17 00:00:00 2001 From: bol-van Date: Tue, 2 Dec 2025 10:49:50 +0300 Subject: [PATCH] nft optimize rules --- common/nft.sh | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/common/nft.sh b/common/nft.sh index 240b458..6b00fcb 100644 --- a/common/nft.sh +++ b/common/nft.sh @@ -328,16 +328,16 @@ nft_apply_flow_offloading() [ "$DISABLE_IPV4" = "1" ] || { # allow only outgoing packets to initiate flow offload - nft_add_rule forward_hook oifname @wanif meta l4proto "{ tcp, udp }" jump flow_offload - nft_add_rule flow_offload ip daddr == @nozapret jump flow_offload_always + nft_add_rule forward_hook meta l4proto "{ tcp, udp }" oifname @wanif jump flow_offload + nft_add_rule flow_offload ip daddr == @nozapret goto flow_offload_always } [ "$DISABLE_IPV6" = "1" ] || { - nft_add_rule forward_hook oifname @wanif6 meta l4proto "{ tcp, udp }" jump flow_offload - nft_add_rule flow_offload ip6 daddr == @nozapret6 jump flow_offload_always + nft_add_rule forward_hook meta l4proto "{ tcp, udp }" oifname @wanif6 jump flow_offload + nft_add_rule flow_offload ip6 daddr == @nozapret6 goto flow_offload_always } nft_add_rule flow_offload jump flow_offload_zapret - nft_add_rule flow_offload_zapret jump flow_offload_always + nft_add_rule flow_offload_zapret goto flow_offload_always } }