Add iptables raw table NOTRACK rules for the VIO port, matching what Paqet already has. Without NOTRACK, conntrack tracks the crafted TCP packets which can cause them to be dropped by hypervisor bridge netfilter (e.g. Proxmox). Added to: boot script, _apply_firewall, _remove_firewall, and install section. Ref #27
272 KiB
272 KiB