ffnord / ffnord-puppet-gateway

Deploy and manage your Freifunk community gateway, mostly compatible with Gluon.
15 stars 13 forks source link

IPv{4,6} forwarding only on devices where it is needed? #70

Open ohrensessel opened 9 years ago

ohrensessel commented 9 years ago

Wouldn't it be much cleaner if we enable forwarding selectively on interfaces where we need it instead of system wide forwarding? as an example: normally you do not need forwarding on your eth0 in a gateway setup.

sargon commented 9 years ago

Yes. The wan-forward part is kind of handle stuff the same way. With the increased space in front of connection tracking we could now enforce dropping these packages directly.