firewall: various enhancements
authorjow <jow@3c298f89-4303-0410-b956-a3cf2f4a3e73>
Mon, 4 Feb 2013 14:38:33 +0000 (14:38 +0000)
committerjow <jow@3c298f89-4303-0410-b956-a3cf2f4a3e73>
Mon, 4 Feb 2013 14:38:33 +0000 (14:38 +0000)
commit6351a51255125f717fae33ff0b2852b0ba3dd551
treedf8e07613004ca3a6247d5d0d89e1339be14a13b
parent6ec4b12517f63923263923141b648f13a5e952a9
firewall: various enhancements

- reduce mssfix related log spam (#10681)
- separate src and dest terminal chains (#11453, #12945)
- disable per-zone custom chains by default, they're rarely used

Additionally introduce options "device", "subnet", "extra", "extra_src" and "extra_dest"
to allow defining zones not related to uci interfaces, e.g. to match "ppp+" or any tcp
traffic to and from a specific port.

git-svn-id: svn://svn.openwrt.org/openwrt/trunk@35484 3c298f89-4303-0410-b956-a3cf2f4a3e73
package/network/config/firewall/Makefile
package/network/config/firewall/files/lib/core_forwarding.sh
package/network/config/firewall/files/lib/core_init.sh
package/network/config/firewall/files/lib/core_interface.sh
package/network/config/firewall/files/lib/core_redirect.sh
package/network/config/firewall/files/lib/core_rule.sh
package/network/config/firewall/files/lib/fw.sh