suricata: improve FW rules (bypass was not working for localhost)
iptables table mangle POSTROUTING/PREROUTING is not triggered for traffic incoming to/outgoing from localhost, so CONNMARK was not set this fix moves setting CONNMARK to filter:suricata table
Please register or sign in to comment