Exclude loopback from conntrack

This commit is contained in:
2019-08-30 00:33:49 +00:00
parent dfeed33f2b
commit 41c2343f75
3 changed files with 18 additions and 0 deletions

View File

@ -92,7 +92,15 @@
-A INPUT -m state --state RELATED,ESTABLISHED -m comment --comment "accept related/established inet6" -j ACCEPT
-A INPUT -m comment --comment "default drop inet6" -j LOG_DROP
COMMIT
*raw
:PREROUTING ACCEPT -
:OUTPUT ACCEPT -
{% if firewall_loopback_notrack %}
-A PREROUTING -i lo -j NOTRACK
-A OUTPUT -o lo -j NOTRACK
{% endif %}
COMMIT
# vim: tw=0

View File

@ -76,7 +76,15 @@
-A INPUT -m state --state RELATED,ESTABLISHED -m comment --comment "accept related/established" -j ACCEPT
-A INPUT -m comment --comment "default drop" -j LOG_DROP
COMMIT
*raw
:PREROUTING ACCEPT -
:OUTPUT ACCEPT -
{% if firewall_loopback_notrack %}
-A PREROUTING -i lo -j NOTRACK
-A OUTPUT -o lo -j NOTRACK
{% endif %}
COMMIT
# vim: tw=0