diff --git a/gestion/gen_confs/firewall.py b/gestion/gen_confs/firewall.py index 6ab43dd7..ccad453a 100755 --- a/gestion/gen_confs/firewall.py +++ b/gestion/gen_confs/firewall.py @@ -466,7 +466,7 @@ class firewall_komaz(firewall_crans) : iptables("-t nat -A PREROUTING -s %s -j ACCEPT" % self.zone_serveur ) iptables("-t nat -A PREROUTING -d %s -j ACCEPT" % self.zone_serveur ) iptables("-t nat -A PREROUTING -i %s -p tcp --dport 80 -s ! %s -j DNAT --to-destination 138.231.136.3:80" % (self.eth_int, self.zone_serveur) ) - iptables("-t nat -A POSTROUTING -o %s -p tcp --dport 80 -s ! %s -d 138.231.136.3 -j SNAT --to-source 138.231.136.4" % (self.eth_int, self.zone_serveur) ) + iptables("-t nat -A POSTROUTING -o %s -p tcp --dport 80 -s 138.231.136.0/21 -d 138.231.136.3 -j SNAT --to-source 138.231.136.4" % self.eth_int ) iptables("-t nat -A PREROUTING -j TEST_MAC-IP") iptables("-t nat -P PREROUTING DROP") iptables("-t nat -P OUTPUT ACCEPT")