Forward Firewall 0.9.9.7: reordered INPUT POLICY.
authorAlexander Marx <amarx@ipfire.org>
Wed, 12 Jun 2013 13:05:31 +0000 (15:05 +0200)
committerMichael Tremer <michael.tremer@ipfire.org>
Fri, 9 Aug 2013 12:15:28 +0000 (14:15 +0200)
src/initscripts/init.d/firewall

index 94b869dd6b9d7bea35cea0a6aec8d68e23bf3d9f..a7d258a5643dd4eabb64c659ba5e3b3650cd2616 100644 (file)
@@ -273,16 +273,6 @@ case "$1" in
                /etc/sysconfig/firewall.local start
        fi
 
-       /sbin/iptables -A INPUT -j DROP -m comment --comment "DROP_INPUT"
-
-       if [ "$DROPINPUT" == "on" ]; then
-               /sbin/iptables -A INPUT   -m limit --limit 10/minute -j LOG --log-prefix "DROP_INPUT"
-       fi
-       if [ "$DROPFORWARD" == "on" ]; then
-               /sbin/iptables -A FORWARD -m limit --limit 10/minute -j LOG --log-prefix "DROP_FORWARD"
-       fi
-       /sbin/iptables -A FORWARD -j DROP -m comment --comment "DROP_FORWARD"
-
        #POLICY CHAIN
        /sbin/iptables -N POLICYIN
        /sbin/iptables -A INPUT -j POLICYIN