X-Git-Url: https://git.rohieb.name/openwrt.git/blobdiff_plain/de748ce4bd06d004fa0870d822042b9e545333e8..c3001723cbd07c232d514eec233336a1978ce159:/package/base-files/default/etc/init.d/S45firewall diff --git a/package/base-files/default/etc/init.d/S45firewall b/package/base-files/default/etc/init.d/S45firewall index c9986011a..2942f3118 100755 --- a/package/base-files/default/etc/init.d/S45firewall +++ b/package/base-files/default/etc/init.d/S45firewall @@ -5,13 +5,13 @@ ${FAILSAFE:+exit} . /etc/functions.sh . /etc/network.overrides -[ -e /etc/config/network ] && . /etc/config/network +[ "$FAILSAFE" != "true" -a -e /etc/config/network ] && . /etc/config/network WAN=$(nvram get wan_ifname) LAN=$(nvram get lan_ifname) ## CLEAR TABLES -for T in filter nat mangle; do +for T in filter nat; do iptables -t $T -F iptables -t $T -X done @@ -82,7 +82,7 @@ iptables -t nat -N postrouting_rule # allow iptables -A FORWARD -i br0 -o br0 -j ACCEPT - [ -z "$WAN" ] || iptables -A FORWARD -i $LAN -o $WAN -j ACCEPT + [ -z "$WAN" ] || iptables -A FORWARD -i $iface -o $WAN -j ACCEPT # reject (what to do with anything not allowed earlier) # uses the default -P DROP