Exclude loopback from conntrack

This commit is contained in:
Ryan Cavicchioni 2019-08-30 00:33:49 +00:00
parent dfeed33f2b
commit 41c2343f75
Signed by: ryanc
GPG Key ID: 877EEDAF9245103D
3 changed files with 18 additions and 0 deletions

View File

@ -29,6 +29,8 @@ firewall_drop_icmp_flood: true
firewall_limit_icmp_flood_seconds: 1 firewall_limit_icmp_flood_seconds: 1
firewall_limit_icmp_flood_hitcount: 6 firewall_limit_icmp_flood_hitcount: 6
firewall_loopback_notrack: true
firewall_limited_tcp_ports: {} firewall_limited_tcp_ports: {}
firewall_allowed_tcp_ports: {} firewall_allowed_tcp_ports: {}

View File

@ -92,7 +92,15 @@
-A INPUT -m state --state RELATED,ESTABLISHED -m comment --comment "accept related/established inet6" -j ACCEPT -A INPUT -m state --state RELATED,ESTABLISHED -m comment --comment "accept related/established inet6" -j ACCEPT
-A INPUT -m comment --comment "default drop inet6" -j LOG_DROP -A INPUT -m comment --comment "default drop inet6" -j LOG_DROP
COMMIT
*raw
:PREROUTING ACCEPT -
:OUTPUT ACCEPT -
{% if firewall_loopback_notrack %}
-A PREROUTING -i lo -j NOTRACK
-A OUTPUT -o lo -j NOTRACK
{% endif %}
COMMIT COMMIT
# vim: tw=0 # vim: tw=0

View File

@ -76,7 +76,15 @@
-A INPUT -m state --state RELATED,ESTABLISHED -m comment --comment "accept related/established" -j ACCEPT -A INPUT -m state --state RELATED,ESTABLISHED -m comment --comment "accept related/established" -j ACCEPT
-A INPUT -m comment --comment "default drop" -j LOG_DROP -A INPUT -m comment --comment "default drop" -j LOG_DROP
COMMIT
*raw
:PREROUTING ACCEPT -
:OUTPUT ACCEPT -
{% if firewall_loopback_notrack %}
-A PREROUTING -i lo -j NOTRACK
-A OUTPUT -o lo -j NOTRACK
{% endif %}
COMMIT COMMIT
# vim: tw=0 # vim: tw=0