mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-04-28 03:33:25 +02:00
iptables: Remove OPENSSL{PHYSICAL,VIRTUAL} chains which are unused.
This commit is contained in:
@@ -140,11 +140,8 @@ iptables_init() {
|
|||||||
/sbin/iptables -N IPSECINPUT
|
/sbin/iptables -N IPSECINPUT
|
||||||
/sbin/iptables -N IPSECFORWARD
|
/sbin/iptables -N IPSECFORWARD
|
||||||
/sbin/iptables -N IPSECOUTPUT
|
/sbin/iptables -N IPSECOUTPUT
|
||||||
/sbin/iptables -N OPENSSLVIRTUAL
|
|
||||||
/sbin/iptables -A INPUT -j IPSECINPUT
|
/sbin/iptables -A INPUT -j IPSECINPUT
|
||||||
/sbin/iptables -A INPUT -j OPENSSLVIRTUAL -m comment --comment "OPENSSLVIRTUAL INPUT"
|
|
||||||
/sbin/iptables -A FORWARD -j IPSECFORWARD
|
/sbin/iptables -A FORWARD -j IPSECFORWARD
|
||||||
/sbin/iptables -A FORWARD -j OPENSSLVIRTUAL -m comment --comment "OPENSSLVIRTUAL FORWARD"
|
|
||||||
/sbin/iptables -A OUTPUT -j IPSECOUTPUT
|
/sbin/iptables -A OUTPUT -j IPSECOUTPUT
|
||||||
/sbin/iptables -t nat -N IPSECNAT
|
/sbin/iptables -t nat -N IPSECNAT
|
||||||
/sbin/iptables -t nat -A POSTROUTING -j IPSECNAT
|
/sbin/iptables -t nat -A POSTROUTING -j IPSECNAT
|
||||||
@@ -172,10 +169,6 @@ iptables_init() {
|
|||||||
/sbin/iptables -N FORWARDFW
|
/sbin/iptables -N FORWARDFW
|
||||||
/sbin/iptables -A FORWARD -j FORWARDFW
|
/sbin/iptables -A FORWARD -j FORWARDFW
|
||||||
|
|
||||||
# OPenSSL
|
|
||||||
/sbin/iptables -N OPENSSLPHYSICAL
|
|
||||||
/sbin/iptables -A INPUT -j OPENSSLPHYSICAL
|
|
||||||
|
|
||||||
# RED chain, used for the red interface
|
# RED chain, used for the red interface
|
||||||
/sbin/iptables -N REDINPUT
|
/sbin/iptables -N REDINPUT
|
||||||
/sbin/iptables -A INPUT -j REDINPUT
|
/sbin/iptables -A INPUT -j REDINPUT
|
||||||
|
|||||||
Reference in New Issue
Block a user