Merge pull request #4983 from bosu/fw-stop-fix

firewall: clear rpfilter on stop
This commit is contained in:
William A. Kennington III 2014-11-14 00:14:27 -08:00
commit d0e15cc575

View file

@ -187,6 +187,12 @@ let
# Clean up after added ruleset
ip46tables -D INPUT -j nixos-fw 2>/dev/null || true
${optionalString (kernelHasRPFilter && cfg.checkReversePath) ''
if ! ip46tables -D PREROUTING -t raw -m rpfilter --invert -j DROP; then
echo "<2>failed to stop rpfilter support" >&2
fi
''}
${cfg.extraStopCommands}
'';