From 79c141ff43e11045e11288a018a580609e189aa9 Mon Sep 17 00:00:00 2001 From: Michael Tremer Date: Wed, 24 Jun 2015 18:40:27 +0200 Subject: [PATCH] firewall: Only propagate ASSURED and DESTROY CT events to user-space Signed-off-by: Michael Tremer --- src/initscripts/init.d/firewall | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/initscripts/init.d/firewall b/src/initscripts/init.d/firewall index 8ca02bc9d1..28443599a5 100644 --- a/src/initscripts/init.d/firewall +++ b/src/initscripts/init.d/firewall @@ -21,9 +21,11 @@ iptables_init() { iptables -F iptables -t nat -F iptables -t mangle -F + iptables -t raw -F iptables -X iptables -t nat -X iptables -t mangle -X + iptables -t raw -X # Set up policies iptables -P INPUT DROP @@ -295,6 +297,9 @@ iptables_init() { if [ ! -e "/var/ipfire/red/active" ]; then iptables_red_down fi + + # Only propagate assured and destroy CT events to user-space + iptables -t raw -A PREROUTING -j CT --ctevents assured,destroy } iptables_red_up() { -- 2.39.5