Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Long time ago we were REJECTing INVALID packets as a *first* rule. That was removed in f03c76e because for example ICMPv6 Echo reply can be considered INVALID by conntrack even it's OK (RHBZ#806017). This time we are going to DROP INVALID packets as a *last but one* rule, just before we REJECT everything (that hasn't matched any rule).
- Loading branch information