Skip to content
Snippets Groups Projects
  • Jo-Philipp Wich's avatar
    2daab45c
    firewall3: drop support for automatic NOTRACK rules · 2daab45c
    Jo-Philipp Wich authored
    
    Update to current HEAD in order to drop automatic generation of per-zone
    NOTRACK rules.
    
    The NOTRACK rules used to provide a little performance improvement but the
    later introduction of the netfilter conntrack cache made those rules largely
    unnecessary. Additionally, those rules caused various issues which broke
    stateful firewalling in some scenarios.
    
    Signed-off-by: default avatarJo-Philipp Wich <jo@mein.io>
    2daab45c
    History
    firewall3: drop support for automatic NOTRACK rules
    Jo-Philipp Wich authored
    
    Update to current HEAD in order to drop automatic generation of per-zone
    NOTRACK rules.
    
    The NOTRACK rules used to provide a little performance improvement but the
    later introduction of the netfilter conntrack cache made those rules largely
    unnecessary. Additionally, those rules caused various issues which broke
    stateful firewalling in some scenarios.
    
    Signed-off-by: default avatarJo-Philipp Wich <jo@mein.io>
Makefile 1.88 KiB