#!/bin/sh # Masquerade mesh clients' INTERNET-bound (exit-node) traffic only; preserve site-to-site source. iptables -t nat -F MESH-EXIT 2>/dev/null || iptables -t nat -N MESH-EXIT iptables -t nat -A MESH-EXIT -d 10.0.0.0/8 -j RETURN iptables -t nat -A MESH-EXIT -d 172.16.0.0/12 -j RETURN iptables -t nat -A MESH-EXIT -d 192.168.0.0/16 -j RETURN iptables -t nat -A MESH-EXIT -d 100.64.0.0/10 -j RETURN iptables -t nat -A MESH-EXIT -j MASQUERADE iptables -t nat -C POSTROUTING -s 100.64.0.0/10 -o eth0 -j MESH-EXIT 2>/dev/null \ || iptables -t nat -A POSTROUTING -s 100.64.0.0/10 -o eth0 -j MESH-EXIT