]> git.ipfire.org Git - ipfire-2.x.git/commitdiff
firewall: Flush SYN_FLOOD_PROTECTION
authorMichael Tremer <michael.tremer@ipfire.org>
Mon, 7 Oct 2024 09:13:12 +0000 (09:13 +0000)
committerMichael Tremer <michael.tremer@ipfire.org>
Tue, 8 Oct 2024 08:43:23 +0000 (08:43 +0000)
This chain was not flushed when the firewall was being reloaded which
made any ports appear as open when rules have been disabled or deleted.

This has no security implications, but nevertheless isn't right.

Reported-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
config/firewall/rules.pl

index e38f772428569c2207eb3fe4d547cf998a087cf5..c414f172ce8fdbe58f5b2aa7fd446e11024c1d43 100644 (file)
@@ -221,6 +221,7 @@ sub flush {
        run("$IPTABLES -t nat -F $CHAIN_NAT_SOURCE");
        run("$IPTABLES -t nat -F $CHAIN_NAT_DESTINATION");
        run("$IPTABLES -t mangle -F $CHAIN_MANGLE_NAT_DESTINATION_FIX");
+       run("$IPTABLES -t raw -F SYN_FLOOD_PROTECT");
 }
 
 sub buildrules {