Hi,
I use a radius server (freeradius) which can insert dynamic rules to ppp filter chain and I would like to have a return rule at the end of the ppp chain (to forward chain) but the radius put the dynamic rules at the end of the ppp chain (after the static return rule). I can drag the return rule (with a find command for moving) but can’t move it at all as i can’t count dynamic rules.
Example: 2 user = 4 dynamic rules + 1 static (return to forward chain)
The static rule has been created. When both 2 users logging in 4 dynamic rules has been created by the mt (command from freeradius), after the static rules. It is wrong because static rule must be at the end of the ppp chain.
Does anybody have an idea about counting dynamic rules or any other solution for the above? Is it possible to send rules to be taken at the beginning of the chain from freeradius to mt? Alternatively, can I change mt firewall settings that drop all packets which don’t get accept command or can I count active pppoe sessions from interface list?
Thanks for your help in advance
gyoztes