BCP38: don't slow down established connections (#2838)

Enabling BCP38 causes an iptables rule to be inserted before this rule:
ACCEPT     all  --  anywhere             anywhere             ID:66773300 ctstate RELATED,ESTABLISHED

This makes all forwarded packets go through the BCP38 ipset match, which slows
down download speed from 440 Mbit/s to 340 Mbit/s.

Only apply BCP38 match rules if state is NEW.

Bump package version.

Signed-off-by: Török Edwin <edwin@skylable.com>
This commit is contained in:
Török Edwin
2016-06-12 16:09:05 +03:00
committed by Toke Høiland-Jørgensen
parent 9093379603
commit 0b2b462ae0
2 changed files with 7 additions and 7 deletions
+1 -1
View File
@@ -6,7 +6,7 @@
include $(TOPDIR)/rules.mk
PKG_NAME:=bcp38
PKG_VERSION:=4
PKG_VERSION:=5
PKG_RELEASE:=1
PKG_LICENCE:=GPL-3.0+