From 0f1cda211c441d17e212ee7c881e0d0014238155 Mon Sep 17 00:00:00 2001 From: Jonatan Schlag Date: Sat, 11 Mar 2017 09:10:39 +0100 Subject: [PATCH] Disable netfilter on all bridges per default Fixes: #11301 Signed-off-by: Jonatan Schlag Signed-off-by: Michael Tremer --- config/etc/sysctl.conf | 5 +++++ config/rootfiles/core/110/filelists/files | 1 + 2 files changed, 6 insertions(+) diff --git a/config/etc/sysctl.conf b/config/etc/sysctl.conf index e2e3d81b03..ad562404fb 100644 --- a/config/etc/sysctl.conf +++ b/config/etc/sysctl.conf @@ -34,3 +34,8 @@ net.ipv6.conf.default.disable_ipv6 = 1 # Enable netfilter accounting net.netfilter.nf_conntrack_acct=1 + +# Disable netfilter on bridges. +net.bridge.bridge-nf-call-ip6tables = 0 +net.bridge.bridge-nf-call-iptables = 0 +net.bridge.bridge-nf-call-arptables = 0 diff --git a/config/rootfiles/core/110/filelists/files b/config/rootfiles/core/110/filelists/files index b996e48aa4..f06b6d5de5 100644 --- a/config/rootfiles/core/110/filelists/files +++ b/config/rootfiles/core/110/filelists/files @@ -2,6 +2,7 @@ etc/system-release etc/issue etc/httpd/conf/server-tuning.conf etc/rc.d/init.d/unbound +etc/sysctl.conf srv/web/ipfire/cgi-bin/index.cgi srv/web/ipfire/cgi-bin/vpnmain.cgi usr/lib/libssp.so.0 -- 2.39.5