summaryrefslogtreecommitdiffstats
path: root/etc/inc/filter.inc
diff options
context:
space:
mode:
Diffstat (limited to 'etc/inc/filter.inc')
-rw-r--r--etc/inc/filter.inc22
1 files changed, 9 insertions, 13 deletions
diff --git a/etc/inc/filter.inc b/etc/inc/filter.inc
index 7d67a5b..6ef7870 100644
--- a/etc/inc/filter.inc
+++ b/etc/inc/filter.inc
@@ -1337,12 +1337,10 @@ function generate_user_filter_rule_arr($rule, $ngcounter) {
$line = generate_user_filter_rule($rule, $ngcounter);
$ret['rule'] = $line;
$ret['interface'] = $rule['interface'];
- if ($line[0] != '#') {
- if($rule['descr'] != "" and $line != "")
- $ret['descr'] = "label \"USER_RULE: " . str_replace('"', '', $rule['descr']) . "\"";
- else
- $ret['descr'] = "label \"USER_RULE\"";
- }
+ if($rule['descr'] != "" and $line != "")
+ $ret['descr'] = "label \"USER_RULE: " . str_replace('"', '', $rule['descr']) . "\"";
+ else
+ $ret['descr'] = "label \"USER_RULE\"";
$ret['ackq'] = get_ack_queue($rule['interface']);
return $ret;
@@ -1395,7 +1393,7 @@ function generate_user_filter_rule($rule, $ngcounter) {
/* don't include disabled rules */
if (isset($rule['disabled'])) {
- return "# rule " . $rule['descr'] . " disabled ";
+ return "# rule " . $rule['descr'] . " disabled \n";
}
$pptpdcfg = $config['pptpd'];
@@ -1433,8 +1431,6 @@ function generate_user_filter_rule($rule, $ngcounter) {
if($config['pppoe']['n_pppoe_units'] <> "")
$nif = $config['pppoe']['n_pppoe_units'];
$ispppoe = true;
- } else if(!isset($rule['interface'])) {
- return '# Interface empty for rule: '.$rule['descr'];
} else {
/* Check to see if the interface is opt and in our opt list */
@@ -2891,10 +2887,10 @@ anchor "imspector"
anchor "miniupnpd"
#---------------------------------------------------------------------------
-# default deny rules
+# default rules (just to be sure)
#---------------------------------------------------------------------------
-block in $log quick all label "Default deny rule"
-block out $log quick all label "Default deny rule"
+block in $log quick all label "Default block all just to be sure."
+block out $log quick all label "Default block all just to be sure."
EOD;
@@ -3298,4 +3294,4 @@ function return_vpn_subnet($adr) {
}
-?>
+?> \ No newline at end of file
OpenPOWER on IntegriCloud