]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/commitdiff
firewall: Always enable connection tracking for GRE
authorMichael Tremer <michael.tremer@ipfire.org>
Tue, 16 Jun 2020 15:40:44 +0000 (15:40 +0000)
committerMichael Tremer <michael.tremer@ipfire.org>
Fri, 19 Jun 2020 17:14:59 +0000 (17:14 +0000)
If this module is not being loaded, the kernel will mark any
GRE connection as INVALID in connection tracking, which will
be then silently dropped by a firewall rule.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
config/rootfiles/core/147/filelists/files
src/initscripts/system/firewall

index ce4e5176819cd602789659e1ec55e95db3d971f4..ec47d36d35bf591e8998a4c42e28959b769ce58d 100644 (file)
@@ -2,3 +2,4 @@ etc/system-release
 etc/issue
 srv/web/ipfire/cgi-bin/credits.cgi
 var/ipfire/langs
+etc/rc.d/init.d/firewall
index 00512d9fa6015c1804543500f331d75c44fdfc90..b0890c71731b8c90747227b6cacc540c5485289e 100644 (file)
@@ -96,6 +96,9 @@ iptables_init() {
 
        # Conntrack helpers (https://home.regit.org/netfilter-en/secure-use-of-helpers/)
 
+       # GRE (always enabled)
+       modprobe nf_conntrack_proto_gre
+
        # SIP
        if [ "${CONNTRACK_SIP}" = "on" ]; then
                modprobe nf_nat_sip