Skip to content
Snippets Groups Projects
Commit 2daab45c authored by Jo-Philipp Wich's avatar Jo-Philipp Wich
Browse files

firewall3: drop support for automatic NOTRACK rules


Update to current HEAD in order to drop automatic generation of per-zone
NOTRACK rules.

The NOTRACK rules used to provide a little performance improvement but the
later introduction of the netfilter conntrack cache made those rules largely
unnecessary. Additionally, those rules caused various issues which broke
stateful firewalling in some scenarios.

Signed-off-by: default avatarJo-Philipp Wich <jo@mein.io>
parent a6781ef4
No related branches found
No related tags found
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment