From 4ab01b74cda620f03dbe93df035dddfa79bbc29e Mon Sep 17 00:00:00 2001 From: Wang Sen Di Date: Wed, 3 Dec 2025 15:02:39 +0800 Subject: [PATCH] - --- netflow/iptables.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/netflow/iptables.sh b/netflow/iptables.sh index b573123..bfb775e 100644 --- a/netflow/iptables.sh +++ b/netflow/iptables.sh @@ -50,8 +50,8 @@ __main() { for cgid in "${_cgroup_ids[@]}"; do for cmd in iptables ip6tables; do $cmd -t mangle -N "$_chain" 2>/dev/null || true - if ! $cmd -t mangle -C OUTPUT -m cgroup --cgroup "$cgid" -j "$_chain" 2>/dev/null; then - $cmd -t mangle -A OUTPUT -m cgroup --cgroup "$cgid" -j "$_chain" + if ! $cmd -t mangle -C OUTPUT -m cgroup --cgroup "$cgid" -m addrtype ! --dst-type LOCAL -j "$_chain" 2>/dev/null; then + $cmd -t mangle -A OUTPUT -m cgroup --cgroup "$cgid" -m addrtype ! --dst-type LOCAL -j "$_chain" fi if ! $cmd -t mangle -C "$_chain" -j RETURN 2>/dev/null; then $cmd -t mangle -A "$_chain" -j RETURN