From: Dietmar Maurer Date: Wed, 5 Mar 2014 10:49:52 +0000 (+0100) Subject: add optimization as last step X-Git-Url: https://git.proxmox.com/?p=pve-firewall.git;a=commitdiff_plain;h=98aa911ec4c4c420ddf107f97ffc26bd312d1dd5 add optimization as last step --- diff --git a/src/PVE/Firewall.pm b/src/PVE/Firewall.pm index ff50d04..d09cf8d 100644 --- a/src/PVE/Firewall.pm +++ b/src/PVE/Firewall.pm @@ -1593,7 +1593,6 @@ sub compile { ruleset_create_chain($ruleset, "PVEFW-OUTPUT"); ruleset_create_chain($ruleset, "PVEFW-FORWARD"); - ruleset_addrule($ruleset, "PVEFW-FORWARD", "-m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT"); my $hostfw_options = {}; my $hostfw_conf = {}; @@ -1667,6 +1666,9 @@ sub compile { } } + # fixme: this is an optimization? if so, we should also drop INVALID packages? + ruleset_insertrule($ruleset, "PVEFW-FORWARD", "-m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT"); + return wantarray ? ($ruleset, $hostfw_conf) : $ruleset; }