]> git.ipfire.org Git - ipfire-2.x.git/commitdiff
firewall: remove conntrack_gre helper
authorArne Fitzenreiter <arne_f@ipfire.org>
Fri, 2 Jul 2021 05:53:24 +0000 (07:53 +0200)
committerArne Fitzenreiter <arne_f@ipfire.org>
Mon, 5 Jul 2021 05:42:40 +0000 (07:42 +0200)
this is not exist in kernel-5.10

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
src/initscripts/system/firewall

index 1e558ee86a55b2013ac014266138cce42488b84e..baa39abe13b00461b1f11e2e83b8ecebd3a54a9e 100644 (file)
@@ -98,11 +98,6 @@ iptables_init() {
        iptables -t raw -N CONNTRACK
        iptables -t raw -A PREROUTING -j CONNTRACK
 
-       # Conntrack helper (https://home.regit.org/netfilter-en/secure-use-of-helpers/)
-
-       # GRE (always enabled)
-       modprobe nf_conntrack_proto_gre
-
        # Fix for braindead ISPs
        iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu