On Di, 10.05.22 17:59, Kamil Jońca (kjonca@xxxxx) wrote: > Maybe I was not clear. > I have ("internal") interfaces qemu1 and qemu2. and interface eth ("external") > I wat to nat traffic from interface qemu1 via eth , but I do not want > nat traffic from interface qemu2 via eth2/ > > How to achieve this? hmm, eth? eth2? is the latter a typo? Assuming it is a typo: set IPMasquerade=yes only in the .network file that matches qemu1, not the one matching qemu2. > > If this does not deal in interfaces, but in IP addresses instead, no > > need to involve networkd. Just define the firewall outside of > > networkd? > Of course. Like most nontrivial things I want to do. > That was my point. But why involve a callout at all if it's not dynamic? Lennart -- Lennart Poettering, Berlin