]> git.ipfire.org Git - people/ms/ipfire-2.x.git/commit
firewall: Only check relevant bits for NAT fix rules
authorMichael Tremer <michael.tremer@ipfire.org>
Tue, 21 Sep 2021 18:13:02 +0000 (19:13 +0100)
committerMichael Tremer <michael.tremer@ipfire.org>
Tue, 21 Sep 2021 18:17:21 +0000 (19:17 +0100)
commite7cde5392597776487cb82a1edce6f30271a8584
tree1c148f2f325d373c031040329a9a5cc985dd3c32
parent6d8cc5a74eef140b28c62b23b6973c06b15ec8f2
firewall: Only check relevant bits for NAT fix rules

In order to use the highest two bits for surciata bypass, we will need
to make sure that whenever we compare any other marks, we do not care
about anything else.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
config/firewall/rules.pl
src/initscripts/system/firewall