base-files: disable bridge firewalling by default
SVN-Revision: 19214
This commit is contained in:
parent
a86a28841c
commit
bf9917d651
2 changed files with 8 additions and 3 deletions
|
@ -1,5 +1,5 @@
|
||||||
#
|
#
|
||||||
# Copyright (C) 2007-2009 OpenWrt.org
|
# Copyright (C) 2007-2010 OpenWrt.org
|
||||||
#
|
#
|
||||||
# This is free software, licensed under the GNU General Public License v2.
|
# This is free software, licensed under the GNU General Public License v2.
|
||||||
# See /LICENSE for more information.
|
# See /LICENSE for more information.
|
||||||
|
@ -9,7 +9,7 @@ include $(TOPDIR)/rules.mk
|
||||||
include $(INCLUDE_DIR)/kernel.mk
|
include $(INCLUDE_DIR)/kernel.mk
|
||||||
|
|
||||||
PKG_NAME:=base-files
|
PKG_NAME:=base-files
|
||||||
PKG_RELEASE:=35
|
PKG_RELEASE:=36
|
||||||
|
|
||||||
PKG_FILE_DEPENDS:=$(PLATFORM_DIR)/ $(GENERIC_PLATFORM_DIR)/base-files/
|
PKG_FILE_DEPENDS:=$(PLATFORM_DIR)/ $(GENERIC_PLATFORM_DIR)/base-files/
|
||||||
|
|
||||||
|
|
|
@ -4,7 +4,7 @@ net.ipv4.conf.all.arp_ignore=1
|
||||||
net.ipv4.ip_forward=1
|
net.ipv4.ip_forward=1
|
||||||
net.ipv4.icmp_echo_ignore_broadcasts=1
|
net.ipv4.icmp_echo_ignore_broadcasts=1
|
||||||
net.ipv4.icmp_ignore_bogus_error_responses=1
|
net.ipv4.icmp_ignore_bogus_error_responses=1
|
||||||
net.ipv4.tcp_ecn=0
|
net.ipv4.tcp_ecn=0
|
||||||
net.ipv4.tcp_fin_timeout=30
|
net.ipv4.tcp_fin_timeout=30
|
||||||
net.ipv4.tcp_keepalive_time=120
|
net.ipv4.tcp_keepalive_time=120
|
||||||
net.ipv4.tcp_syncookies=1
|
net.ipv4.tcp_syncookies=1
|
||||||
|
@ -17,3 +17,8 @@ net.ipv4.netfilter.ip_conntrack_tcp_timeout_established=3600
|
||||||
net.ipv4.netfilter.ip_conntrack_udp_timeout=60
|
net.ipv4.netfilter.ip_conntrack_udp_timeout=60
|
||||||
net.ipv4.netfilter.ip_conntrack_udp_timeout_stream=180
|
net.ipv4.netfilter.ip_conntrack_udp_timeout_stream=180
|
||||||
# net.ipv6.conf.all.forwarding=1
|
# net.ipv6.conf.all.forwarding=1
|
||||||
|
|
||||||
|
# disable bridge firewalling by default
|
||||||
|
net.bridge.bridge-nf-call-arptables=0
|
||||||
|
net.bridge.bridge-nf-call-ip6tables=0
|
||||||
|
net.bridge.bridge-nf-call-iptables=0
|
||||||
|
|
Loading…
Reference in a new issue