openwrt / firewall4

[MIRROR] OpenWrt nftables firewall
https://git.openwrt.org/?p=project/firewall4.git;
17 stars 13 forks source link

WIP Stop spilling ICMP unreach to unrelated networks. #12

Closed brada4 closed 10 months ago

brada4 commented 1 year ago

@jow- please tell if formatting should be this or cryptic readback from nft l r .. reject icmp enters stack via icmp_send, subject to routes and (permitted) output, thus 'drop' activity can be one line down, though i find no reason for it to send on wrong iface. Test: try to isolate network forwarding with reject. Misfeature dates back to iptables reject target incepticon. i know tests due, will adjust on feedback. S-o-b: A P <n...m>