From 6dcfe8743593a9035bb477530f5cbaba354403bd Mon Sep 17 00:00:00 2001 From: John Southworth Date: Mon, 12 Dec 2011 15:17:28 -0800 Subject: Setup filter for VRRP vmac interfaces --- scripts/firewall/firewall.init.in | 6 ++++++ 1 file changed, 6 insertions(+) (limited to 'scripts') diff --git a/scripts/firewall/firewall.init.in b/scripts/firewall/firewall.init.in index 07c32f8..bcc23ba 100644 --- a/scripts/firewall/firewall.init.in +++ b/scripts/firewall/firewall.init.in @@ -48,6 +48,12 @@ start () { for mod in ${modules[@]} ; do modprobe --syslog $mod done + # setup vrrp backup transition chain + # we need to filter traffic to the vrrp mac addresses + # on the vrrp backup router before we do anything else. + iptables -t raw -N VYATTA_VRRP_FILTER + iptables -t raw -A VYATTA_VRRP_FILTER -j RETURN + iptables -t raw -A PREROUTING -j VYATTA_VRRP_FILTER # set up notrack chains/rules for IPv4 # by default, nothing is tracked. -- cgit v1.2.3