Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | main/nftables: Updating init script | Ben Allen | 2016-01-19 | 1 | -44/+11 |
| | | | | | | | - Tidy up panic function to a single inet (combined ip and ipv6) table. - Use policy drop for each chain in the panic function instead of a drop rule. This way a user could manually add in rules later allowing explicit access. - Instead of a clear function, include 'flush ruleset' in the output of the save function. This way loading the saved rulesets is fully atomic, instead of two commands. - Stop is the only function that needs to be able to flush ruleset, so run 'nft flush ruleset' directly, and remove the clear function. | ||||
* | main/nftables: Update init script | Ben Allen | 2016-01-11 | 1 | -105/+87 |
| | | | | Updating main/nftables init script. Based on the newer Gentoo init script: https://gitweb.gentoo.org/repo/gentoo.git/tree/net-firewall/nftables/files/nftables.init-r2. Merged nftables.sh from Gentoo's version into the init script itself, and removed the legacy functionality. Adding descriptions for each action as well. | ||||
* | main/nftables: moved from testing | Eivind Uggedal | 2015-09-15 | 1 | -0/+150 |
Since linux 3.18 the elaborate clear logic is no longer needed. Replace it with the safer: nft flush ruleset |