Forward Firewall: added drop rules to firewall's stop script so that collectd is...
authorAlexander Marx <amarx@ipfire.org>
Mon, 15 Apr 2013 07:50:39 +0000 (09:50 +0200)
committerMichael Tremer <michael.tremer@ipfire.org>
Fri, 9 Aug 2013 12:13:10 +0000 (14:13 +0200)
src/initscripts/init.d/firewall

index 57bdef9016517ce24dc882f7e5646dd4e76f3973..24dee132a2ce8e6d83835a55c71ab3967f21278e 100644 (file)
@@ -316,6 +316,13 @@ case "$1" in
                /sbin/iptables -A FORWARD -m limit --limit 10/minute -j LOG --log-prefix "DROP_FORWARD "
        fi
        /sbin/iptables -A FORWARD -j DROP -m comment --comment "DROP_FORWARD"
+       
+       #Only for firewall Hits statistik
+       /sbin/iptables -A POLICYFWD -j DROP  -m comment --comment "DROP_FORWARD"
+       /sbin/iptables -A POLICYOUT -j DROP  -m comment --comment "DROP_OUTPUT"
+       
+       
+       
        ;;
   stopovpn)
        # stop openvpn