chiark / gitweb /
local.m4: Put the default network stanza at the end.
authorMark Wooding <mdw@distorted.org.uk>
Sun, 9 May 2010 16:09:51 +0000 (17:09 +0100)
committerMark Wooding <mdw@distorted.org.uk>
Sun, 9 May 2010 16:09:51 +0000 (17:09 +0100)
Otherwise packets get mistakenly classified as being to-untrusted and
stuff doesn't work properly.  Most notably, forwarding between VPN hosts
fails.

local.m4

index 8e7bd1e27e582511c27925159c0c5f95389cd404..0d38497b391b48392c8cf1c02245830f6db1c0dc 100644 (file)
--- a/local.m4
+++ b/local.m4
@@ -38,10 +38,6 @@ m4_divert(-1)m4_dnl
 m4_divert(46)m4_dnl
 ## Networks and routing.
 
-defiface $if_trusted \
-       trusted:172.29.199.0/26 \
-       safe:172.29.199.64/27 \
-       untrusted:default
 defiface $if_untrusted \
        untrusted:172.29.198.0/25
 defvpn $if_vpn safe 172.29.199.128/27 \
@@ -50,6 +46,10 @@ defvpn $if_vpn safe 172.29.199.128/27 \
 defiface $if_iodine untrusted:172.29.198.128/28
 defiface $if_its_mz safe:172.29.199.160/30
 defiface $if_its_pi safe:192.168.0.0/24
+defiface $if_trusted \
+       trusted:172.29.199.0/26 \
+       safe:172.29.199.64/27 \
+       untrusted:default
 
 m4_divert(60)m4_dnl
 ###--------------------------------------------------------------------------