summaryrefslogtreecommitdiff
path: root/templates/firewall
diff options
context:
space:
mode:
authorMohit Mehta <mohit.mehta@vyatta.com>2009-02-13 15:37:34 -0800
committerMohit Mehta <mohit.mehta@vyatta.com>2009-02-13 15:37:34 -0800
commitaf24ef45b9bea36b44a95273a3b5688a405ac0c0 (patch)
treedc8a78495a9abc08bf2e8d6b591ecb9e8cf2c0d9 /templates/firewall
parentde14ea1af63db350e7174f75c9ace4fb13ded6bd (diff)
downloadvyatta-cfg-firewall-af24ef45b9bea36b44a95273a3b5688a405ac0c0.tar.gz
vyatta-cfg-firewall-af24ef45b9bea36b44a95273a3b5688a405ac0c0.zip
Fix Bug 4074 firewall broadcast ping parameter needs to be clarified
make behavior as documented i.e. icmp broadcast pings are ignored unless 'firewall broadcast-ping' is set to 'enable' by user
Diffstat (limited to 'templates/firewall')
-rw-r--r--templates/firewall/broadcast-ping/node.def10
1 files changed, 5 insertions, 5 deletions
diff --git a/templates/firewall/broadcast-ping/node.def b/templates/firewall/broadcast-ping/node.def
index 594786c..3cf7e00 100644
--- a/templates/firewall/broadcast-ping/node.def
+++ b/templates/firewall/broadcast-ping/node.def
@@ -12,23 +12,23 @@ syntax:expression: $VAR(@) in "enable", "disable"; "broadcast-ping must be enabl
create:
if [ x$VAR(@) == xenable ]; then
- sudo sh -c "echo 1 > \
+ sudo sh -c "echo 0 > \
/proc/sys/net/ipv4/icmp_echo_ignore_broadcasts"
else
- sudo sh -c "echo 0 > \
+ sudo sh -c "echo 1 > \
/proc/sys/net/ipv4/icmp_echo_ignore_broadcasts"
fi
update:
if [ x$VAR(@) == xenable ]; then
- sudo sh -c "echo 1 > \
+ sudo sh -c "echo 0 > \
/proc/sys/net/ipv4/icmp_echo_ignore_broadcasts"
else
- sudo sh -c "echo 0 > \
+ sudo sh -c "echo 1 > \
/proc/sys/net/ipv4/icmp_echo_ignore_broadcasts"
fi
delete:
- sudo sh -c "echo 0 > \
+ sudo sh -c "echo 1 > \
/proc/sys/net/ipv4/icmp_echo_ignore_broadcasts"