mirror of
https://gitlab.com/shorewall/code.git
synced 2025-06-08 18:57:07 +02:00
Exempt IPv4 DHCP broadcasts from rpfilter
Signed-off-by: Tom Eastep <teastep@shorewall.net>
This commit is contained in:
parent
c47abe416a
commit
e7792fc868
@ -918,7 +918,17 @@ sub add_common_rules ( $$ ) {
|
|||||||
$target = $policy eq 'REJECT' ? 'reject' : $policy;
|
$target = $policy eq 'REJECT' ? 'reject' : $policy;
|
||||||
}
|
}
|
||||||
|
|
||||||
add_ijump( ensure_mangle_chain( 'rpfilter' ),
|
my $rpfilterref = ensure_mangle_chain( 'rpfilter' );
|
||||||
|
|
||||||
|
add_ijump( $rpfilterref,
|
||||||
|
j => 'RETURN',
|
||||||
|
s => NILIPv4,
|
||||||
|
p => UDP,
|
||||||
|
dport => 67,
|
||||||
|
sport => 68
|
||||||
|
) if $family == F_IPV4;
|
||||||
|
|
||||||
|
add_ijump( $rpfilterref,
|
||||||
j => $target,
|
j => $target,
|
||||||
rpfilter => '--validmark --invert',
|
rpfilter => '--validmark --invert',
|
||||||
state_imatch 'NEW,RELATED,INVALID',
|
state_imatch 'NEW,RELATED,INVALID',
|
||||||
|
Loading…
x
Reference in New Issue
Block a user