remove optimization which accepts unrelated traffic
authorDietmar Maurer <dietmar@proxmox.com>
Wed, 19 Mar 2014 08:11:17 +0000 (09:11 +0100)
committerDietmar Maurer <dietmar@proxmox.com>
Wed, 19 Mar 2014 08:11:17 +0000 (09:11 +0100)
Removing this alsmo make ips filter easier.

src/PVE/Firewall.pm

index 4406824..ba4559d 100644 (file)
@@ -1827,9 +1827,6 @@ sub compile {
        }
     }
 
-    # fixme: this is an optimization? if so, we should also drop INVALID packages?
-    ruleset_insertrule($ruleset, "PVEFW-FORWARD", "-m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT");
-
     # fixme: what log level should we use here?
     my $loglevel = get_option_log_level($hostfw_options, "log_level_out");