firewall: extend nat reflection support
authorjow <jow@3c298f89-4303-0410-b956-a3cf2f4a3e73>
Tue, 4 Dec 2012 15:24:21 +0000 (15:24 +0000)
committerjow <jow@3c298f89-4303-0410-b956-a3cf2f4a3e73>
Tue, 4 Dec 2012 15:24:21 +0000 (15:24 +0000)
commit8e0547608f41c5557528fa8858a112f4252046a9
tree5c3f4bde9b6c471dab299b8acca2412230326684
parentc4a99b6ef610bf17a5daccf5fc36e94790cc597b
firewall: extend nat reflection support

- use comment match to keep track of per-network rules
- setup reflection for any interface which is part of a masqueraded zone, not just "wan"
- delete per-network reflection rules if network is brought down

git-svn-id: svn://svn.openwrt.org/openwrt/trunk@34472 3c298f89-4303-0410-b956-a3cf2f4a3e73
package/network/config/firewall/Makefile
package/network/config/firewall/files/reflection.hotplug