firewall: drop invalid by default, remove chain indirection, fix invert flags (#21738)
authorjow <jow@3c298f89-4303-0410-b956-a3cf2f4a3e73>
Fri, 29 Jan 2016 17:26:41 +0000 (17:26 +0000)
committerjow <jow@3c298f89-4303-0410-b956-a3cf2f4a3e73>
Fri, 29 Jan 2016 17:26:41 +0000 (17:26 +0000)
commitb234590e1de1619400831224612b33e848bf7f03
treef735bd4deac0aecc1018a9120c184e740c36aeae
parent07023de0ba89172a8fd27038a6473fcbbae3fe0b
firewall: drop invalid by default, remove chain indirection, fix invert flags (#21738)

* Enable drop_invalid by default to catch unnatted packets (#21738)
* Fix processing of inversions for -i, -o, -s, -d and -p flags
* Remove delegate_* chain indirection but rely on xt_id to identify own rules

Signed-off-by: Jo-Philipp Wich <jow@openwrt.org>
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@48551 3c298f89-4303-0410-b956-a3cf2f4a3e73
package/network/config/firewall/Makefile