spice - firewall and interfaces

magnum

Member
Aug 31, 2021
42
0
11
35
Hello,

i'm currently trying to get spice running:

Code:
auto vmbr1
iface vmbr1 inet dhcp
        bridge-ports eno1
        post-up echo 1 > /proc/sys/net/ipv4/ip_forward
        post-up iptables -t nat -A PREROUTING -i vmbr1 -p tcp -m multiport ! --dport 22,8006,3128 -j DNAT --to 192.0.0.2
        post-up iptables -t nat -A PREROUTING -i vmbr1 -p udp -j DNAT --to 192.0.0.2
        post-up ip route replace default via 10.152.47.254 dev vmbr1
        post-down ip route replace default via 10.152.116.254 dev vmbr3


Is it correct to add 3128 as an exception on tcp forwarding to pfsense