]> git.proxmox.com Git - pve-firewall.git/commit - src/PVE/Firewall.pm
ndp: use PVEFW-SET-ACCEPT-MARK and move rules further down
authorWolfgang Bumiller <w.bumiller@proxmox.com>
Tue, 1 Mar 2016 11:20:17 +0000 (12:20 +0100)
committerDietmar Maurer <dietmar@proxmox.com>
Wed, 2 Mar 2016 06:22:20 +0000 (07:22 +0100)
commite84159203fa54c72cb4270789bc40e556c169ffa
tree270173fc565b8de178542c3dc2f6a64945198708
parenta1c04f71a77c47bb520de3d596d0855bb48aee89
ndp: use PVEFW-SET-ACCEPT-MARK and move rules further down

On host level: moved NDP to after connection tracking and
switched to RETURN instead of ACCEPT.

On VM level:
The output direction now uses the accept-mark like the dhcp
option does, too.
Also moved NDP rules below the macfilter & ipset rules.
src/PVE/Firewall.pm