]> git.ipfire.org Git - people/jschlag/network.git/commitdiff
firewall: Enable ECN by default
authorMichael Tremer <michael.tremer@ipfire.org>
Thu, 1 Mar 2018 15:21:13 +0000 (15:21 +0000)
committerMichael Tremer <michael.tremer@ipfire.org>
Thu, 1 Mar 2018 21:07:45 +0000 (21:07 +0000)
Apple has tried this and it seems to be safe now

https://www.ietf.org/proceedings/98/slides/slides-98-maprg-tcp-ecn-experience-with-enabling-ecn-on-the-internet-padma-bhooma-00.pdf

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
man/firewall-settings.xml
src/functions/functions.constants-firewall

index 6870d1fe3609b007e23bf7da6d64a200a274bc61..60626368c25df69bffed4aed366d594d21916d8d 100644 (file)
 
                        <varlistentry>
                                <term>
-                                       <varname>FIREWALL_USE_ECN</varname> = [true|<emphasis>false</emphasis>]
+                                       <varname>FIREWALL_USE_ECN</varname> = [<emphasis>true</emphasis>|false]
                                </term>
 
                                <listitem>
index f1eaf505b5531c10b0c80a9dcc275ffe3597457a..d42189aae9179d8c186207744238844e5ce42363 100644 (file)
@@ -74,7 +74,7 @@ FIREWALL_ACCEPT_ICMP_REDIRECTS="false"
 FIREWALL_CONFIG_PARAMS="${FIREWALL_CONFIG_PARAMS} FIREWALL_ACCEPT_ICMP_REDIRECTS"
 
 # ECN (Explicit Congestion Notification)
-FIREWALL_USE_ECN="false"
+FIREWALL_USE_ECN="true"
 FIREWALL_CONFIG_PARAMS="${FIREWALL_CONFIG_PARAMS} FIREWALL_USE_ECN"
 
 # Path MTU discovery