diff options
author | Ermal Luçi <eri@pfsense.org> | 2008-08-01 21:09:49 +0000 |
---|---|---|
committer | Ermal Luçi <eri@pfsense.org> | 2008-08-01 21:09:49 +0000 |
commit | 97b8e3fc89e25a3bebe0884fc01f37b38da9fe2c (patch) | |
tree | d2a70947bfd2d8cdffb7d8075192afd46076690d /etc | |
parent | 2f69e11c5ea5c85e1202b92bb45ebc710bc8281a (diff) | |
download | pfsense-97b8e3fc89e25a3bebe0884fc01f37b38da9fe2c.zip pfsense-97b8e3fc89e25a3bebe0884fc01f37b38da9fe2c.tar.gz |
Do not generate antispoof for virtual interfaces.
Diffstat (limited to 'etc')
-rw-r--r-- | etc/inc/filter.inc | 5 |
1 files changed, 3 insertions, 2 deletions
diff --git a/etc/inc/filter.inc b/etc/inc/filter.inc index b778a21..2b57578 100644 --- a/etc/inc/filter.inc +++ b/etc/inc/filter.inc @@ -435,6 +435,7 @@ function generate_optcfg_array() $oic['alias-address'] = $oc['alias-address']; $oic['alias-subnet'] = $oc['alias-subnet']; $oic['gateway'] = $oc['gateway']; + $oic['spoofcheck'] = "yes"; $FilterIflist[$if] = $oic; } @@ -2104,8 +2105,8 @@ EOD; break; } } - if ($oc['ip'] && !($isbridged) && !isset($config['bridge']['filteringbridge'])) - $ipfrules .= filter_rules_spoofcheck_generate($on, $oc['if'], $oc['sa'], $oc['sn'], $log); + if ($oc['ip'] && !($isbridged) && !isset($config['bridge']['filteringbridge']) && isset($oc['spoofcheck'])) + $ipfrules .= filter_rules_spoofcheck_generate($on, $oc['if'], $oc['sa'], $oc['sn'], $log); /* block private networks ? */ |