summaryrefslogtreecommitdiff
path: root/scripts/firewall/firewall.init.in
diff options
context:
space:
mode:
authorAn-Cheng Huang <ancheng@vyatta.com>2008-04-08 16:34:09 -0700
committerAn-Cheng Huang <ancheng@vyatta.com>2008-04-08 16:34:09 -0700
commit041c76680a23aa1204cc08d3720d2957f45a9fac (patch)
treeeea9985ce2e2525dffdd7db6ce74083cc048a8a5 /scripts/firewall/firewall.init.in
parent7271fce2882df7a1251608203099fc54862b78d1 (diff)
downloadvyatta-cfg-firewall-041c76680a23aa1204cc08d3720d2957f45a9fac.tar.gz
vyatta-cfg-firewall-041c76680a23aa1204cc08d3720d2957f45a9fac.zip
add post-firewall hook for other features
Diffstat (limited to 'scripts/firewall/firewall.init.in')
-rw-r--r--scripts/firewall/firewall.init.in6
1 files changed, 6 insertions, 0 deletions
diff --git a/scripts/firewall/firewall.init.in b/scripts/firewall/firewall.init.in
index acd951a..9f365db 100644
--- a/scripts/firewall/firewall.init.in
+++ b/scripts/firewall/firewall.init.in
@@ -52,6 +52,12 @@ start () {
# by default, nothing is tracked.
iptables -t raw -A PREROUTING -j NOTRACK
iptables -t raw -A OUTPUT -j NOTRACK
+
+ # set up post-firewall hook
+ iptables -N VYATTA_POST_FW_HOOK
+ iptables -A VYATTA_POST_FW_HOOK -j ACCEPT
+ iptables -A INPUT -j VYATTA_POST_FW_HOOK
+ iptables -A FORWARD -j VYATTA_POST_FW_HOOK
}
case "$ACTION" in