modules/clerie-firewall: enable connection tracking
This commit is contained in:
parent
f05567cbce
commit
7f84597b56
@ -24,6 +24,9 @@ let
|
|||||||
|
|
||||||
ip46tables -N forward-filter
|
ip46tables -N forward-filter
|
||||||
|
|
||||||
|
# Allow packets from existing connections
|
||||||
|
ip46tables -A forward-filter -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
||||||
|
|
||||||
${cfg.extraForwardFilterCommands}
|
${cfg.extraForwardFilterCommands}
|
||||||
|
|
||||||
ip46tables -A FORWARD -j forward-filter
|
ip46tables -A FORWARD -j forward-filter
|
||||||
|
Loading…
Reference in New Issue
Block a user