b9122f648e
Upon the receipt of a valid SPA packet, a check is done to make sure that a jump rule from the appropriate built-in iptables chains exists to the fwknop chains. Such rules could have been deleted by other manipulations of the iptables policy, so it is important to ensure they exist. Running in foreground (-f) mode, here is an illustration of the jump rule being added after it got deleted: SPA Packet from IP: 127.0.0.1 received. Added jump rule from chain: INPUT to chain: FWKNOP_INPUT Added Rule to FWKNOP_INPUT for 127.0.0.1, tcp/22 expires at 1313680648