From e7a3c8c142932e0e16b3aee99bf74ecfc2d61753 Mon Sep 17 00:00:00 2001 From: bol-van Date: Wed, 1 Jun 2022 16:31:52 +0300 Subject: [PATCH] nft: fix chains deletion on stop_fw --- common/nft.sh | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/common/nft.sh b/common/nft.sh index ead3495..152b3b6 100644 --- a/common/nft.sh +++ b/common/nft.sh @@ -109,10 +109,11 @@ cat << EOF | nft -f - 2>/dev/null delete chain inet $ZAPRET_NFT_TABLE forward delete chain inet $ZAPRET_NFT_TABLE input delete chain inet $ZAPRET_NFT_TABLE postrouting - delete chain inet $ZAPRET_NFT_TABLE predefrag delete chain inet $ZAPRET_NFT_TABLE flow_offload delete chain inet $ZAPRET_NFT_TABLE localnet_protect EOF +# unfortunately this approach breaks udp desync of the connection initiating packet (new, first one) +# delete chain inet $ZAPRET_NFT_TABLE predefrag } nft_del_flowtable() {