diff --git a/sisr1/tp06-firewall/current_ruleset.nft b/sisr1/tp06-firewall/current_ruleset.nft index 2c612d7..5bf849f 100644 --- a/sisr1/tp06-firewall/current_ruleset.nft +++ b/sisr1/tp06-firewall/current_ruleset.nft @@ -25,7 +25,7 @@ table ip ipfilter { chain routing { type filter hook forward priority filter; policy drop; icmp type echo-request iif $lanif oif $dmzif accept - icmp type echo-request iif $dmzif oif $lanif accept + icmp type echo-reply iif $dmzif oif $lanif accept } chain system_out { type filter hook output priority filter; policy drop; diff --git a/sisr1/tp06-firewall/fw_part3.nft b/sisr1/tp06-firewall/fw_part3.nft index 2c612d7..5bf849f 100644 --- a/sisr1/tp06-firewall/fw_part3.nft +++ b/sisr1/tp06-firewall/fw_part3.nft @@ -25,7 +25,7 @@ table ip ipfilter { chain routing { type filter hook forward priority filter; policy drop; icmp type echo-request iif $lanif oif $dmzif accept - icmp type echo-request iif $dmzif oif $lanif accept + icmp type echo-reply iif $dmzif oif $lanif accept } chain system_out { type filter hook output priority filter; policy drop;