Alin Nastac
c86490605c
netfilter: add iptables-mod-rpfilter package
...
Unlike /proc/sys/net/ipv4/conf/INTF/rp_filter flag, rule iptables -t raw
-I PREROUTING -m rpfilter --invert -j DROP prevents conntrack table to
become full when a packet flood with randomly selected source IP addresses
is received from the lan side.
Signed-off-by: Alin Nastac <alin.nastac@gmail.com>
(cherry picked from commit d8748e537f11ab5f2b5e2ed25d94baa5ce353984)
2017-12-13 16:23:38 +01:00
..
2017-10-05 21:16:25 +02:00
2017-01-14 18:57:13 +01:00
2017-02-21 16:16:25 +01:00
2015-03-29 07:29:18 +00:00
2017-01-05 11:09:12 +01:00
2013-08-27 12:02:58 +00:00
2017-01-13 10:23:43 +01:00
2017-01-16 09:11:56 +01:00
2015-06-24 10:57:14 +00:00
2017-12-13 14:56:57 +01:00
2017-12-13 14:32:21 +01:00
2017-12-13 14:31:36 +01:00
2017-07-14 23:36:50 +02:00
2017-05-16 17:38:08 +02:00
2017-12-13 14:27:44 +01:00
2017-12-13 15:00:42 +01:00
2017-12-12 11:10:47 +01:00
2017-07-05 12:49:21 +02:00
2017-12-13 16:23:38 +01:00
2015-09-07 08:03:34 +00:00
2015-03-29 07:29:18 +00:00
2017-12-13 15:19:04 +01:00
2016-04-15 10:26:36 +02:00
2017-02-01 16:07:30 +01:00
2015-03-26 10:57:56 +00:00
2017-12-13 14:56:57 +01:00
2017-01-05 11:09:12 +01:00
2015-09-16 12:38:16 +00:00
2017-01-05 11:09:12 +01:00
2017-01-27 10:09:50 +01:00
2015-02-09 12:09:31 +00:00
2017-12-13 14:32:21 +01:00
2016-10-13 17:04:43 +02:00
2017-01-05 11:09:12 +01:00
2016-12-17 10:36:25 +01:00
2017-12-13 15:00:21 +01:00
2015-03-29 07:29:18 +00:00
2017-12-13 15:27:36 +01:00
2013-05-09 20:50:49 +00:00
2017-01-05 11:09:13 +01:00
2015-04-16 12:18:26 +00:00
2017-10-18 11:54:32 +03:00