start() {
include /lib/network
scan_interfaces
+ config_load /var/state/network
config_get WAN wan ifname
config_get WANDEV wan device
# uses the default -P DROP
### MASQ
- iptables -t nat -A PREROUTING -m state --state NEW -j NEW
+ iptables -t nat -A PREROUTING -m state --state NEW -p tcp -j NEW
iptables -t nat -A PREROUTING -j prerouting_rule
[ -z "$WAN" ] || iptables -t nat -A PREROUTING -i "$WAN" -j prerouting_wan
iptables -t nat -A POSTROUTING -j postrouting_rule