firewall: drop invalid by default, remove chain indirection, fix invert flags (#21738)
authorJo-Philipp Wich <jow@openwrt.org>
Fri, 29 Jan 2016 17:26:41 +0000 (17:26 +0000)
committerJo-Philipp Wich <jow@openwrt.org>
Fri, 29 Jan 2016 17:26:41 +0000 (17:26 +0000)
commitd4721e8d8f00b569000c7f224831c1bec7406a0c
treef735bd4deac0aecc1018a9120c184e740c36aeae
parent09a834a2d3dcde3becc7781637733357ba87808a
firewall: drop invalid by default, remove chain indirection, fix invert flags (#21738)

* Enable drop_invalid by default to catch unnatted packets (#21738)
* Fix processing of inversions for -i, -o, -s, -d and -p flags
* Remove delegate_* chain indirection but rely on xt_id to identify own rules

Signed-off-by: Jo-Philipp Wich <jow@openwrt.org>
SVN-Revision: 48551
package/network/config/firewall/Makefile