From 8f1086e5c9b2a66a8774ff8688517a34cd75d968 Mon Sep 17 00:00:00 2001 From: oleg Date: Sun, 5 Jun 2005 06:20:09 +0000 Subject: relates connections should be mss clamped too git-svn-id: svn://svn.openwrt.org/openwrt/trunk/openwrt@1142 3c298f89-4303-0410-b956-a3cf2f4a3e73 --- target/default/target_skeleton/etc/init.d/S45firewall | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'target/default/target_skeleton/etc') diff --git a/target/default/target_skeleton/etc/init.d/S45firewall b/target/default/target_skeleton/etc/init.d/S45firewall index 072f411a9..8f9b9404e 100755 --- a/target/default/target_skeleton/etc/init.d/S45firewall +++ b/target/default/target_skeleton/etc/init.d/S45firewall @@ -63,8 +63,8 @@ iptables -t nat -N postrouting_rule # base case iptables -P FORWARD DROP iptables -A FORWARD -m state --state INVALID -j DROP - iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu + iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT # allow iptables -A FORWARD -i br0 -o br0 -j ACCEPT -- cgit v1.2.3