firewall: flush conntrack table after changing interface rules
authorJo-Philipp Wich <jow@openwrt.org>
Mon, 28 Jan 2013 15:53:44 +0000 (15:53 +0000)
committerJo-Philipp Wich <jow@openwrt.org>
Mon, 28 Jan 2013 15:53:44 +0000 (15:53 +0000)
SVN-Revision: 35348

package/network/config/firewall/Makefile
package/network/config/firewall/files/lib/core_interface.sh

index 1cfc734a32e5b5db9c45f2bba4c7da59fedba3b4..fce0a808cd1dc5b52e8b599fce5ee9538f36ebcb 100644 (file)
@@ -1,5 +1,5 @@
 #
-# Copyright (C) 2008-2012 OpenWrt.org
+# Copyright (C) 2008-2013 OpenWrt.org
 #
 # This is free software, licensed under the GNU General Public License v2.
 # See /LICENSE for more information.
@@ -9,7 +9,7 @@ include $(TOPDIR)/rules.mk
 PKG_NAME:=firewall
 
 PKG_VERSION:=2
-PKG_RELEASE:=56
+PKG_RELEASE:=57
 
 include $(INCLUDE_DIR)/package.mk
 
index 3d6718431fb2f0fecce58f505bdc3c856ab96c6d..7400e2d35112b065a52c82c10cdf0e29e047af8f 100644 (file)
@@ -106,6 +106,9 @@ fw_configure_interface() {
                fw $action $mode r PREROUTING ${chain}_notrack    $ { -i "$ifname" $inet }
                fw $action $mode n POSTROUTING ${chain}_nat       $ { -o "$ifname" $onet }
 
+               # Flush conntrack table
+               echo f >/proc/net/nf_conntrack 2>/dev/null
+
                lock -u /var/run/firewall-interface.lock
        }