diff options
author | Kevin Darbyshire-Bryant <kdarbyshirebryant@users.noreply.github.com> | 2017-04-12 09:34:02 +0100 |
---|---|---|
committer | Toke Høiland-Jørgensen <toke@toke.dk> | 2017-04-12 10:34:02 +0200 |
commit | d30e249d4c7d9c3654059074decd643c1a4839e7 (patch) | |
tree | 41c5d0095796b6c3b4d4213cb7f1e72afb60d1e7 /net/bcp38/files | |
parent | cf75d8a0f975d646d6d1173561cd52c5184a15f2 (diff) |
bcp38: iptables 1.6.1 compatibility (#4248)
-m state has been removed, now use -m conntrack --ctstate
Signed-off-by: Kevin Darbyshire-Bryant <kevin@darbyshire-bryant.me.uk>
Diffstat (limited to 'net/bcp38/files')
-rwxr-xr-x | net/bcp38/files/run.sh | 12 |
1 files changed, 6 insertions, 6 deletions
diff --git a/net/bcp38/files/run.sh b/net/bcp38/files/run.sh index 00d50342e..736ea52c6 100755 --- a/net/bcp38/files/run.sh +++ b/net/bcp38/files/run.sh @@ -72,9 +72,9 @@ setup_iptables() iptables -N "$IPTABLES_CHAIN" 2>/dev/null iptables -F "$IPTABLES_CHAIN" 2>/dev/null - iptables -I output_rule -m state --state NEW -j "$IPTABLES_CHAIN" - iptables -I input_rule -m state --state NEW -j "$IPTABLES_CHAIN" - iptables -I forwarding_rule -m state --state NEW -j "$IPTABLES_CHAIN" + iptables -I output_rule -m conntrack --ctstate NEW -j "$IPTABLES_CHAIN" + iptables -I input_rule -m conntrack --ctstate NEW -j "$IPTABLES_CHAIN" + iptables -I forwarding_rule -m conntrack --ctstate NEW -j "$IPTABLES_CHAIN" # always accept DHCP traffic iptables -A "$IPTABLES_CHAIN" -p udp --dport 67:68 --sport 67:68 -j RETURN @@ -90,9 +90,9 @@ destroy_ipset() destroy_iptables() { - iptables -D output_rule -m state --state NEW -j "$IPTABLES_CHAIN" 2>/dev/null - iptables -D input_rule -m state --state NEW -j "$IPTABLES_CHAIN" 2>/dev/null - iptables -D forwarding_rule -m state --state NEW -j "$IPTABLES_CHAIN" 2>/dev/null + iptables -D output_rule -m conntrack --ctstate NEW -j "$IPTABLES_CHAIN" 2>/dev/null + iptables -D input_rule -m conntrack --ctstate NEW -j "$IPTABLES_CHAIN" 2>/dev/null + iptables -D forwarding_rule -m conntrack --ctstate NEW -j "$IPTABLES_CHAIN" 2>/dev/null iptables -F "$IPTABLES_CHAIN" 2>/dev/null iptables -X "$IPTABLES_CHAIN" 2>/dev/null } |