Есть vps на centos 8.5 (firewalld 0.9.3) и там точно такие же правила работают
а на Rocky Linux 9.1 (firewalld 1.1.1) не работают
ipv6 отключено, SELinux отключен, net.ipv4.ip_forward = 1
Куда еще посмотреть?
public (active)
target: default
icmp-block-inversion: no
interfaces: eth0
sources:
services:
ports:
protocols:
forward: no
masquerade: no
forward-ports:
source-ports:
icmp-blocks:
rich rules:
rule source ipset="work" service name="ssh" accept
rule family="ipv4" source address="172.25.11.0/30" masquerade
rule source ipset="work" service name="wireguard" accept
work (active)
target: default
icmp-block-inversion: no
interfaces: wg0
sources:
services: dhcp dns
ports:
protocols: icmp
forward: no
masquerade: no
forward-ports:
source-ports:
icmp-blocks:
rich rules:
filter_FWD_work_REJECT: "IN=wg0 OUT=eth0 MAC= SRC=172.25.11.2 DST=173.194.220.103 LEN=127