lede-packages-rs

git clone git://archive.git.mtrnord.blog/MTRNord/lede-packages-rs.git
Log | Files | Refs | README | LICENSE

commit 0b2b462ae0ff78b25704eb06f5a36f5105082e0f
parent 9093379603f97d08fbf55434d4468e1f947c5651
Author: Török Edwin <edwintorok@users.noreply.github.com>
Date:   Sun, 12 Jun 2016 16:09:05 +0300

BCP38: don't slow down established connections (#2838)

Enabling BCP38 causes an iptables rule to be inserted before this rule:
ACCEPT     all  --  anywhere             anywhere             ID:66773300 ctstate RELATED,ESTABLISHED

This makes all forwarded packets go through the BCP38 ipset match, which slows
down download speed from 440 Mbit/s to 340 Mbit/s.

Only apply BCP38 match rules if state is NEW.

Bump package version.

Signed-off-by: Török Edwin <edwin@skylable.com>
Diffstat:
Mnet/bcp38/Makefile | 2+-
Mnet/bcp38/files/run.sh | 12++++++------
2 files changed, 7 insertions(+), 7 deletions(-)

diff --git a/net/bcp38/Makefile b/net/bcp38/Makefile @@ -6,7 +6,7 @@ include $(TOPDIR)/rules.mk PKG_NAME:=bcp38 -PKG_VERSION:=4 +PKG_VERSION:=5 PKG_RELEASE:=1 PKG_LICENCE:=GPL-3.0+ diff --git a/net/bcp38/files/run.sh b/net/bcp38/files/run.sh @@ -72,9 +72,9 @@ setup_iptables() iptables -N "$IPTABLES_CHAIN" 2>/dev/null iptables -F "$IPTABLES_CHAIN" 2>/dev/null - iptables -I output_rule -j "$IPTABLES_CHAIN" - iptables -I input_rule -j "$IPTABLES_CHAIN" - iptables -I forwarding_rule -j "$IPTABLES_CHAIN" + iptables -I output_rule -m state --state NEW -j "$IPTABLES_CHAIN" + iptables -I input_rule -m state --state NEW -j "$IPTABLES_CHAIN" + iptables -I forwarding_rule -m state --state NEW -j "$IPTABLES_CHAIN" # always accept DHCP traffic iptables -A "$IPTABLES_CHAIN" -p udp --dport 67:68 --sport 67:68 -j RETURN @@ -90,9 +90,9 @@ destroy_ipset() destroy_iptables() { - iptables -D output_rule -j "$IPTABLES_CHAIN" 2>/dev/null - iptables -D input_rule -j "$IPTABLES_CHAIN" 2>/dev/null - iptables -D forwarding_rule -j "$IPTABLES_CHAIN" 2>/dev/null + iptables -D output_rule -m state --state NEW -j "$IPTABLES_CHAIN" 2>/dev/null + iptables -D input_rule -m state --state NEW -j "$IPTABLES_CHAIN" 2>/dev/null + iptables -D forwarding_rule -m state --state NEW -j "$IPTABLES_CHAIN" 2>/dev/null iptables -F "$IPTABLES_CHAIN" 2>/dev/null iptables -X "$IPTABLES_CHAIN" 2>/dev/null }