diff options
author | Gaurav Sinha <gaurav.sinha@vyatta.com> | 2012-03-16 21:03:51 -0700 |
---|---|---|
committer | Gaurav Sinha <gaurav.sinha@vyatta.com> | 2012-03-16 21:03:51 -0700 |
commit | b4c313d953660b8a70ccfda0b260fd81a6089976 (patch) | |
tree | ccde995e180aaf5ac594328aba551b2356405ad9 /scripts/vyatta-conntrack-timeouts.pl | |
parent | b791c5f35b7723c139b83b492dd20406cdd42784 (diff) | |
download | vyatta-conntrack-b4c313d953660b8a70ccfda0b260fd81a6089976.tar.gz vyatta-conntrack-b4c313d953660b8a70ccfda0b260fd81a6089976.zip |
use add instead of create, use inet, pre-pend protocol to iptables rule
Diffstat (limited to 'scripts/vyatta-conntrack-timeouts.pl')
-rw-r--r-- | scripts/vyatta-conntrack-timeouts.pl | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/scripts/vyatta-conntrack-timeouts.pl b/scripts/vyatta-conntrack-timeouts.pl index 24aa4ac..7d0295f 100644 --- a/scripts/vyatta-conntrack-timeouts.pl +++ b/scripts/vyatta-conntrack-timeouts.pl @@ -19,7 +19,7 @@ my $debug_flag = 0; # Enable sending debug output to syslog. my $syslog_flag = 0; -my $nfct = "/opt/vyatta/sbin/nfct"; +my $nfct = "sudo /opt/vyatta/sbin/nfct"; my ($create, $delete, $update); my $CTERROR = "Conntrack timeout error:"; GetOptions("create=s" => \$create, @@ -92,7 +92,7 @@ sub remove_timeout_policy { # iptables -I PREROUTING -t raw -s 1.1.1.1 -d 2.2.2.2 -j CT --timeout policy1 sub apply_timeout_policy { my ($rule_string, $timeout_policy) = @_; - my $nfct_timeout_cmd = "$nfct timeout create $timeout_policy"; + my $nfct_timeout_cmd = "$nfct timeout add $timeout_policy"; my @tokens = split (' ', $timeout_policy); my $iptables_cmd1 = "iptables -I PREROUTING -t raw $rule_string -j CT --timeout $tokens[0]"; my $iptables_cmd2 = "iptables -I OUTPUT -t raw $rule_string -j CT --timeout $tokens[0]"; |