The forward rule only accepted iifname=eno1 oifname=eth0 ct status=dnat, which worked when port-forwards always landed on a LAN host. Docker DNAT routes to docker0, so external traffic to 26900 was being DNAT'd correctly but then dropped at the forward filter. Drop the oifname constraint — the prerouting DNAT rule already controls what gets forwarded; the filter doesn't need to second-guess it. |
||
|---|---|---|
| .. | ||
| adguard.nix | ||
| arr-interconnect.nix | ||
| authelia.nix | ||
| bazarr.nix | ||
| cloudflare-ddns.md | ||
| cloudflare-ddns.nix | ||
| crowdsec.nix | ||
| game-servers.nix | ||
| go2rtc.nix | ||
| homepage.nix | ||
| jellyfin.nix | ||
| nginx.nix | ||
| prowlarr.nix | ||
| qbittorrent-nox.nix | ||
| radarr.nix | ||
| router.nix | ||
| server-permissions.nix | ||
| sonarr.nix | ||