Andrew Ruthven a écrit :
Shouldn't that be pre-up instead?I've just tried this and confirmed my suspicion. This will fail if you refer to the interface in your firewall. Since the interface isn't up yet (pre-up) iptables can't find the device to apply the against.
Huh ? AFAIK iptables does not care whether the specified interface is up or even exists. It is just text, possibly including a wildcard (+). Doesn't your script try to extract information about the interface from ifconfig or the like ? Of course this may fail if the interface is not up yet.