commit 0b2b462ae0ff78b25704eb06f5a36f5105082e0f
parent 9093379603f97d08fbf55434d4468e1f947c5651
Author: Török Edwin <edwintorok@users.noreply.github.com>
Date: Sun, 12 Jun 2016 16:09:05 +0300
BCP38: don't slow down established connections (#2838)
Enabling BCP38 causes an iptables rule to be inserted before this rule:
ACCEPT all -- anywhere anywhere ID:66773300 ctstate RELATED,ESTABLISHED
This makes all forwarded packets go through the BCP38 ipset match, which slows
down download speed from 440 Mbit/s to 340 Mbit/s.
Only apply BCP38 match rules if state is NEW.
Bump package version.
Signed-off-by: Török Edwin <edwin@skylable.com>
Diffstat:
2 files changed, 7 insertions(+), 7 deletions(-)
diff --git a/net/bcp38/Makefile b/net/bcp38/Makefile
@@ -6,7 +6,7 @@
include $(TOPDIR)/rules.mk
PKG_NAME:=bcp38
-PKG_VERSION:=4
+PKG_VERSION:=5
PKG_RELEASE:=1
PKG_LICENCE:=GPL-3.0+
diff --git a/net/bcp38/files/run.sh b/net/bcp38/files/run.sh
@@ -72,9 +72,9 @@ setup_iptables()
iptables -N "$IPTABLES_CHAIN" 2>/dev/null
iptables -F "$IPTABLES_CHAIN" 2>/dev/null
- iptables -I output_rule -j "$IPTABLES_CHAIN"
- iptables -I input_rule -j "$IPTABLES_CHAIN"
- iptables -I forwarding_rule -j "$IPTABLES_CHAIN"
+ iptables -I output_rule -m state --state NEW -j "$IPTABLES_CHAIN"
+ iptables -I input_rule -m state --state NEW -j "$IPTABLES_CHAIN"
+ iptables -I forwarding_rule -m state --state NEW -j "$IPTABLES_CHAIN"
# always accept DHCP traffic
iptables -A "$IPTABLES_CHAIN" -p udp --dport 67:68 --sport 67:68 -j RETURN
@@ -90,9 +90,9 @@ destroy_ipset()
destroy_iptables()
{
- iptables -D output_rule -j "$IPTABLES_CHAIN" 2>/dev/null
- iptables -D input_rule -j "$IPTABLES_CHAIN" 2>/dev/null
- iptables -D forwarding_rule -j "$IPTABLES_CHAIN" 2>/dev/null
+ iptables -D output_rule -m state --state NEW -j "$IPTABLES_CHAIN" 2>/dev/null
+ iptables -D input_rule -m state --state NEW -j "$IPTABLES_CHAIN" 2>/dev/null
+ iptables -D forwarding_rule -m state --state NEW -j "$IPTABLES_CHAIN" 2>/dev/null
iptables -F "$IPTABLES_CHAIN" 2>/dev/null
iptables -X "$IPTABLES_CHAIN" 2>/dev/null
}