diff --git a/Shorewall/compiler b/Shorewall/compiler index 1fcb612a8..feda9077c 100755 --- a/Shorewall/compiler +++ b/Shorewall/compiler @@ -3537,9 +3537,6 @@ setup_blacklist() { add_common_rules() { local savelogparms="$LOGPARMS" local broadcasts="$(find_broadcasts) 255.255.255.255 224.0.0.0/4" - local policy - - [ -n "$POLICY_MATCH" ] && policy="-m policy --pol $ipsec --dir in" || policy= # # Populate the smurf chain # @@ -3635,6 +3632,7 @@ __EOF__ for host in $hosts; do ipsec=${host%^*} host=${host#*^} + [ -n "$POLICY_MATCH" ] && policy="-m policy --pol $ipsec --dir in" || policy= interface=${host%%:*} network=${host#*:} @@ -3747,6 +3745,7 @@ __EOF__ for host in $hosts; do ipsec=${host%^*} host=${host#*^} + [ -n "$POLICY_MATCH" ] && policy="-m policy --pol $ipsec --dir in" || policy= interface=${host%%:*} networks=${host#*:}