Closed arnova closed 5 years ago
@abelbeck : This is the "light" version of the previous PR. You ok with this?
@arnova I like the new "light" version, but I would be happy with any of the following options, you decide ...
This "light" version, as is.
As above, but reverse logic and default to off:
- if [ "$FRAG_DROP" != "0" ]; then
+ if [ "$FRAG_DROP" = "1" ]; then
3. Remove ` -f ` fragment support all-together.
Let's do what we have here for now. In case upstream nftables isn't fixed in time we could always reverse the logic to workaround it.
…pping (eg. for broken nftables)