[pve-devel] firewall option nosmurfs and tcpflags

Dietmar Maurer dietmar at proxmox.com
Fri Apr 18 10:30:28 CEST 2014


> just put the rule in PVEFW-FORWARD, after
> 
> -A PVEFW-FORWARD -m conntrack --ctstate INVALID -j DROP -A PVEFW-
> FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

but that only works if the optimize flag is set (else we do not have that rule)?



More information about the pve-devel mailing list