[2/6] firewall: Don't filter output INVALID packets

Message ID 20240418211144.3318938-2-michael.tremer@ipfire.org
State New
Headers
Series [1/6] firewall: Split CONNTRACK chain |

Commit Message

Michael Tremer April 18, 2024, 9:11 p.m. UTC
  This should never cause any problems, but will cause that certain more
complicated featured like SYNPROXY won't work.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
---
 src/initscripts/system/firewall | 1 -
 1 file changed, 1 deletion(-)
  

Patch

diff --git a/src/initscripts/system/firewall b/src/initscripts/system/firewall
index d14466ef0..054d58c01 100644
--- a/src/initscripts/system/firewall
+++ b/src/initscripts/system/firewall
@@ -156,7 +156,6 @@  iptables_init() {
 
 	iptables -N CTOUTPUT
 	iptables -A CTOUTPUT -m conntrack --ctstate ESTABLISHED -j ACCEPT
-	iptables -A CTOUTPUT -m conntrack --ctstate INVALID -j CTINVALID
 	iptables -A CTOUTPUT -p icmp -m conntrack --ctstate RELATED -j ACCEPT
 
 	# Restore any connection marks