firewall: drop invalid by default, remove chain indirection, fix invert flags (#21738)
authorJo-Philipp Wich <jow@openwrt.org>
Fri, 29 Jan 2016 17:26:41 +0000 (17:26 +0000)
committerJo-Philipp Wich <jow@openwrt.org>
Fri, 29 Jan 2016 17:26:41 +0000 (17:26 +0000)
commitb986bf8dfe6f2489cf667b1a7446da15ff28e1c7
treef735bd4deac0aecc1018a9120c184e740c36aeae
parenta593131d49bfed2672ba6d2e889d068bd1d7e38e
firewall: drop invalid by default, remove chain indirection, fix invert flags (#21738)

* Enable drop_invalid by default to catch unnatted packets (#21738)
* Fix processing of inversions for -i, -o, -s, -d and -p flags
* Remove delegate_* chain indirection but rely on xt_id to identify own rules

Signed-off-by: Jo-Philipp Wich <jow@openwrt.org>
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@48551 3c298f89-4303-0410-b956-a3cf2f4a3e73
package/network/config/firewall/Makefile