mirror of
https://github.com/bol-van/zapret.git
synced 2025-05-06 18:50:51 +05:00
drop time exceeded icmp for nfqws-related connections
This commit is contained in:
parent
3ca682e25a
commit
dc1dc5c876
@ -76,9 +76,9 @@ NFQWS_PORTS_UDP=443
|
|||||||
# PKT_IN means connbytes dir reply
|
# PKT_IN means connbytes dir reply
|
||||||
# this is --dpi-desync-cutoff=nX kernel mode implementation for linux. it saves a lot of CPU.
|
# this is --dpi-desync-cutoff=nX kernel mode implementation for linux. it saves a lot of CPU.
|
||||||
NFQWS_TCP_PKT_OUT=$((6+$AUTOHOSTLIST_RETRANS_THRESHOLD))
|
NFQWS_TCP_PKT_OUT=$((6+$AUTOHOSTLIST_RETRANS_THRESHOLD))
|
||||||
NFQWS_TCP_PKT_IN=4
|
NFQWS_TCP_PKT_IN=3
|
||||||
NFQWS_UDP_PKT_OUT=$((6+$AUTOHOSTLIST_RETRANS_THRESHOLD))
|
NFQWS_UDP_PKT_OUT=$((6+$AUTOHOSTLIST_RETRANS_THRESHOLD))
|
||||||
NFQWS_UDP_PKT_IN=1
|
NFQWS_UDP_PKT_IN=0
|
||||||
# redirect outgoing traffic without connbytes limiter and incoming with connbytes limiter
|
# redirect outgoing traffic without connbytes limiter and incoming with connbytes limiter
|
||||||
# normally it's needed only for stateless DPI that matches every packet in a single TCP session
|
# normally it's needed only for stateless DPI that matches every packet in a single TCP session
|
||||||
# typical example are plain HTTP keep alives
|
# typical example are plain HTTP keep alives
|
||||||
@ -129,6 +129,11 @@ INIT_APPLY_FW=1
|
|||||||
# do not work with ipv6
|
# do not work with ipv6
|
||||||
DISABLE_IPV6=1
|
DISABLE_IPV6=1
|
||||||
|
|
||||||
|
# drop icmp time exceeded messages for nfqws tampered connections
|
||||||
|
# in POSTNAT mode this can interfere with default mtr/traceroute in tcp or udp mode. use source port not redirected to nfqws
|
||||||
|
# set to 0 if you are not expecting connection breakage due to icmp in response to TCP SYN or UDP
|
||||||
|
FILTER_TTL_EXPIRED_ICMP=1
|
||||||
|
|
||||||
# select which init script will be used to get ip or host list
|
# select which init script will be used to get ip or host list
|
||||||
# possible values : get_user.sh get_antizapret.sh get_combined.sh get_reestr.sh get_hostlist.sh
|
# possible values : get_user.sh get_antizapret.sh get_combined.sh get_reestr.sh get_hostlist.sh
|
||||||
# comment if not required
|
# comment if not required
|
||||||
|
Loading…
x
Reference in New Issue
Block a user