firewall: drop invalid by default, remove chain indirection, fix invert flags (#21738)
authorJo-Philipp Wich <jow@openwrt.org>
Fri, 29 Jan 2016 17:26:41 +0000 (17:26 +0000)
committerJo-Philipp Wich <jow@openwrt.org>
Fri, 29 Jan 2016 17:26:41 +0000 (17:26 +0000)
commit6064710b90b6138c3471129090ab4192710be42c
treefb38d7f4c14d53b1a8b84cac9d26060c002a69e8
parenta6fe27a59ae41df3fdf048de8d09451484e6a8db
firewall: drop invalid by default, remove chain indirection, fix invert flags (#21738)

* Enable drop_invalid by default to catch unnatted packets (#21738)
* Fix processing of inversions for -i, -o, -s, -d and -p flags
* Remove delegate_* chain indirection but rely on xt_id to identify own rules

Signed-off-by: Jo-Philipp Wich <jow@openwrt.org>
SVN-Revision: 48551
package/network/config/firewall/Makefile