[pve-devel] [PATCH] add ips feature v4

Dietmar Maurer dietmar at proxmox.com
Wed Mar 19 12:17:23 CET 2014


>      # fixme: this is an optimization? if so, we should also drop INVALID
> packages?
> -    ruleset_insertrule($ruleset, "PVEFW-FORWARD", "-m conntrack --ctstate
> RELATED,ESTABLISHED -j ACCEPT");
> -
> +    ruleset_insertrule($ruleset, "PVEFW-FORWARD", "-m conntrack --ctstate
> RELATED,ESTABLISHED -j PVEFW-Accept");
>      # fixme: what log level should we use here?
>      my $loglevel = get_option_log_level($hostfw_options, "log_level_out");

I already remove this rule, so please update first.






More information about the pve-devel mailing list