diff options
author | Chris Buechler <cmb@pfsense.org> | 2012-04-23 00:33:36 -0400 |
---|---|---|
committer | Chris Buechler <cmb@pfsense.org> | 2012-04-23 00:33:36 -0400 |
commit | 912d1887359d90d043cd31648df36272cf40a0ed (patch) | |
tree | 577e2a7084d64609654ccea9dc643f5ad3ab0ddf | |
parent | 58106afc439d9b88e38b81d0d4d90e66fec77249 (diff) | |
download | pfsense-912d1887359d90d043cd31648df36272cf40a0ed.zip pfsense-912d1887359d90d043cd31648df36272cf40a0ed.tar.gz |
go back to scrub rather than "scrub in", the latter breaks MSS clamping for egress traffic the way we use it.
-rw-r--r-- | etc/inc/filter.inc | 6 |
1 files changed, 3 insertions, 3 deletions
diff --git a/etc/inc/filter.inc b/etc/inc/filter.inc index dc7ba96..e497341 100644 --- a/etc/inc/filter.inc +++ b/etc/inc/filter.inc @@ -427,7 +427,7 @@ function filter_generate_scrubing() { if (!empty($config['system']['maxmss'])) $maxmss = $config['system']['maxmss']; - $scrubrules .= "scrub in from any to <vpn_networks> max-mss {$maxmss}\n"; + $scrubrules .= "scrub from any to <vpn_networks> max-mss {$maxmss}\n"; } /* disable scrub option */ foreach ($FilterIflist as $scrubif => $scrubcfg) { @@ -449,9 +449,9 @@ function filter_generate_scrubing() { else $scrubrnid = ""; if(!isset($config['system']['disablescrub'])) - $scrubrules .= "scrub in on \${$scrubcfg['descr']} all {$scrubnodf} {$scrubrnid} {$mssclamp} fragment reassemble\n"; // reassemble all directions + $scrubrules .= "scrub on \${$scrubcfg['descr']} all {$scrubnodf} {$scrubrnid} {$mssclamp} fragment reassemble\n"; // reassemble all directions else if(!empty($mssclamp)) - $scrubrules .= "scrub in on \${$scrubcfg['descr']} {$mssclamp}\n"; + $scrubrules .= "scrub on \${$scrubcfg['descr']} {$mssclamp}\n"; } return $scrubrules; } |