Created
November 16, 2018 11:33
-
-
Save afalko/034966bf72f5da8070d5829c8aac40e4 to your computer and use it in GitHub Desktop.
Iptables working diff
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
--- /boot/config-4.18.18.old 2018-11-15 11:17:08.000000000 -0800 | |
+++ /boot/config-4.18.18 2018-11-16 03:23:06.000000000 -0800 | |
@@ -834,8 +834,8 @@ | |
CONFIG_XFRM_STATISTICS=y | |
CONFIG_XFRM_IPCOMP=y | |
CONFIG_NET_KEY=y | |
-# CONFIG_NET_KEY_MIGRATE is not set | |
-# CONFIG_XDP_SOCKETS is not set | |
+CONFIG_NET_KEY_MIGRATE=y | |
+CONFIG_XDP_SOCKETS=y | |
CONFIG_INET=y | |
CONFIG_IP_MULTICAST=y | |
CONFIG_IP_ADVANCED_ROUTER=y | |
@@ -878,23 +878,32 @@ | |
CONFIG_INET_RAW_DIAG=y | |
CONFIG_INET_DIAG_DESTROY=y | |
CONFIG_TCP_CONG_ADVANCED=y | |
-CONFIG_TCP_CONG_BIC=m | |
+CONFIG_TCP_CONG_BIC=y | |
CONFIG_TCP_CONG_CUBIC=y | |
-CONFIG_TCP_CONG_WESTWOOD=m | |
-CONFIG_TCP_CONG_HTCP=m | |
-# CONFIG_TCP_CONG_HSTCP is not set | |
-# CONFIG_TCP_CONG_HYBLA is not set | |
-# CONFIG_TCP_CONG_VEGAS is not set | |
-# CONFIG_TCP_CONG_NV is not set | |
-# CONFIG_TCP_CONG_SCALABLE is not set | |
-# CONFIG_TCP_CONG_LP is not set | |
-# CONFIG_TCP_CONG_VENO is not set | |
-# CONFIG_TCP_CONG_YEAH is not set | |
-# CONFIG_TCP_CONG_ILLINOIS is not set | |
-# CONFIG_TCP_CONG_DCTCP is not set | |
-# CONFIG_TCP_CONG_CDG is not set | |
-# CONFIG_TCP_CONG_BBR is not set | |
+CONFIG_TCP_CONG_WESTWOOD=y | |
+CONFIG_TCP_CONG_HTCP=y | |
+CONFIG_TCP_CONG_HSTCP=y | |
+CONFIG_TCP_CONG_HYBLA=y | |
+CONFIG_TCP_CONG_VEGAS=y | |
+CONFIG_TCP_CONG_NV=y | |
+CONFIG_TCP_CONG_SCALABLE=y | |
+CONFIG_TCP_CONG_LP=y | |
+CONFIG_TCP_CONG_VENO=y | |
+CONFIG_TCP_CONG_YEAH=y | |
+CONFIG_TCP_CONG_ILLINOIS=y | |
+CONFIG_TCP_CONG_DCTCP=y | |
+CONFIG_TCP_CONG_CDG=y | |
+CONFIG_TCP_CONG_BBR=y | |
+# CONFIG_DEFAULT_BIC is not set | |
CONFIG_DEFAULT_CUBIC=y | |
+# CONFIG_DEFAULT_HTCP is not set | |
+# CONFIG_DEFAULT_HYBLA is not set | |
+# CONFIG_DEFAULT_VEGAS is not set | |
+# CONFIG_DEFAULT_VENO is not set | |
+# CONFIG_DEFAULT_WESTWOOD is not set | |
+# CONFIG_DEFAULT_DCTCP is not set | |
+# CONFIG_DEFAULT_CDG is not set | |
+# CONFIG_DEFAULT_BBR is not set | |
# CONFIG_DEFAULT_RENO is not set | |
CONFIG_DEFAULT_TCP_CONG="cubic" | |
CONFIG_TCP_MD5SIG=y | |
@@ -950,10 +959,10 @@ | |
CONFIG_NETFILTER_NETLINK_LOG=y | |
CONFIG_NF_CONNTRACK=y | |
CONFIG_NF_LOG_COMMON=y | |
-# CONFIG_NF_LOG_NETDEV is not set | |
+CONFIG_NF_LOG_NETDEV=y | |
CONFIG_NETFILTER_CONNCOUNT=y | |
CONFIG_NF_CONNTRACK_MARK=y | |
-# CONFIG_NF_CONNTRACK_SECMARK is not set | |
+CONFIG_NF_CONNTRACK_SECMARK=y | |
CONFIG_NF_CONNTRACK_PROCFS=y | |
CONFIG_NF_CONNTRACK_EVENTS=y | |
CONFIG_NF_CONNTRACK_TIMEOUT=y | |
@@ -963,7 +972,7 @@ | |
CONFIG_NF_CT_PROTO_GRE=y | |
CONFIG_NF_CT_PROTO_SCTP=y | |
CONFIG_NF_CT_PROTO_UDPLITE=y | |
-# CONFIG_NF_CONNTRACK_AMANDA is not set | |
+CONFIG_NF_CONNTRACK_AMANDA=y | |
CONFIG_NF_CONNTRACK_FTP=y | |
CONFIG_NF_CONNTRACK_H323=y | |
CONFIG_NF_CONNTRACK_IRC=y | |
@@ -983,6 +992,7 @@ | |
CONFIG_NF_NAT_PROTO_DCCP=y | |
CONFIG_NF_NAT_PROTO_UDPLITE=y | |
CONFIG_NF_NAT_PROTO_SCTP=y | |
+CONFIG_NF_NAT_AMANDA=y | |
CONFIG_NF_NAT_FTP=y | |
CONFIG_NF_NAT_IRC=y | |
CONFIG_NF_NAT_SIP=y | |
@@ -1036,11 +1046,12 @@ | |
CONFIG_NETFILTER_XT_TARGET_CHECKSUM=y | |
CONFIG_NETFILTER_XT_TARGET_CLASSIFY=y | |
CONFIG_NETFILTER_XT_TARGET_CONNMARK=y | |
+CONFIG_NETFILTER_XT_TARGET_CONNSECMARK=y | |
CONFIG_NETFILTER_XT_TARGET_DSCP=y | |
CONFIG_NETFILTER_XT_TARGET_HL=y | |
CONFIG_NETFILTER_XT_TARGET_HMARK=y | |
CONFIG_NETFILTER_XT_TARGET_IDLETIMER=y | |
-# CONFIG_NETFILTER_XT_TARGET_LED is not set | |
+CONFIG_NETFILTER_XT_TARGET_LED=y | |
CONFIG_NETFILTER_XT_TARGET_LOG=y | |
CONFIG_NETFILTER_XT_TARGET_MARK=y | |
CONFIG_NETFILTER_XT_NAT=y | |
@@ -1050,8 +1061,8 @@ | |
CONFIG_NETFILTER_XT_TARGET_RATEEST=y | |
CONFIG_NETFILTER_XT_TARGET_REDIRECT=y | |
CONFIG_NETFILTER_XT_TARGET_TEE=y | |
-CONFIG_NETFILTER_XT_TARGET_TPROXY=m | |
-# CONFIG_NETFILTER_XT_TARGET_SECMARK is not set | |
+CONFIG_NETFILTER_XT_TARGET_TPROXY=y | |
+CONFIG_NETFILTER_XT_TARGET_SECMARK=y | |
CONFIG_NETFILTER_XT_TARGET_TCPMSS=y | |
CONFIG_NETFILTER_XT_TARGET_TCPOPTSTRIP=y | |
@@ -1079,6 +1090,7 @@ | |
CONFIG_NETFILTER_XT_MATCH_HL=y | |
CONFIG_NETFILTER_XT_MATCH_IPCOMP=y | |
CONFIG_NETFILTER_XT_MATCH_IPRANGE=y | |
+CONFIG_NETFILTER_XT_MATCH_IPVS=y | |
CONFIG_NETFILTER_XT_MATCH_L2TP=y | |
CONFIG_NETFILTER_XT_MATCH_LENGTH=y | |
CONFIG_NETFILTER_XT_MATCH_LIMIT=y | |
@@ -1121,7 +1133,54 @@ | |
CONFIG_IP_SET_HASH_NETPORT=y | |
CONFIG_IP_SET_HASH_NETIFACE=y | |
CONFIG_IP_SET_LIST_SET=y | |
-# CONFIG_IP_VS is not set | |
+CONFIG_IP_VS=y | |
+CONFIG_IP_VS_IPV6=y | |
+# CONFIG_IP_VS_DEBUG is not set | |
+CONFIG_IP_VS_TAB_BITS=12 | |
+ | |
+# | |
+# IPVS transport protocol load balancing support | |
+# | |
+CONFIG_IP_VS_PROTO_TCP=y | |
+CONFIG_IP_VS_PROTO_UDP=y | |
+CONFIG_IP_VS_PROTO_AH_ESP=y | |
+CONFIG_IP_VS_PROTO_ESP=y | |
+CONFIG_IP_VS_PROTO_AH=y | |
+CONFIG_IP_VS_PROTO_SCTP=y | |
+ | |
+# | |
+# IPVS scheduler | |
+# | |
+CONFIG_IP_VS_RR=y | |
+CONFIG_IP_VS_WRR=y | |
+CONFIG_IP_VS_LC=y | |
+CONFIG_IP_VS_WLC=y | |
+CONFIG_IP_VS_FO=y | |
+CONFIG_IP_VS_OVF=y | |
+CONFIG_IP_VS_LBLC=y | |
+CONFIG_IP_VS_LBLCR=y | |
+CONFIG_IP_VS_DH=y | |
+CONFIG_IP_VS_SH=y | |
+CONFIG_IP_VS_MH=y | |
+CONFIG_IP_VS_SED=y | |
+CONFIG_IP_VS_NQ=y | |
+ | |
+# | |
+# IPVS SH scheduler | |
+# | |
+CONFIG_IP_VS_SH_TAB_BITS=8 | |
+ | |
+# | |
+# IPVS MH scheduler | |
+# | |
+CONFIG_IP_VS_MH_TAB_INDEX=12 | |
+ | |
+# | |
+# IPVS application helper | |
+# | |
+CONFIG_IP_VS_FTP=y | |
+CONFIG_IP_VS_NFCT=y | |
+CONFIG_IP_VS_PE_SIP=y | |
# | |
# IP: Netfilter Configuration | |
@@ -1150,24 +1209,24 @@ | |
CONFIG_NF_NAT_PROTO_GRE=y | |
CONFIG_NF_NAT_PPTP=y | |
CONFIG_NF_NAT_H323=y | |
-CONFIG_IP_NF_IPTABLES=m | |
-CONFIG_IP_NF_MATCH_AH=m | |
-CONFIG_IP_NF_MATCH_ECN=m | |
-CONFIG_IP_NF_MATCH_RPFILTER=m | |
-CONFIG_IP_NF_MATCH_TTL=m | |
-CONFIG_IP_NF_FILTER=m | |
-CONFIG_IP_NF_TARGET_REJECT=m | |
-CONFIG_IP_NF_TARGET_SYNPROXY=m | |
-CONFIG_IP_NF_NAT=m | |
-CONFIG_IP_NF_TARGET_MASQUERADE=m | |
-CONFIG_IP_NF_TARGET_NETMAP=m | |
-CONFIG_IP_NF_TARGET_REDIRECT=m | |
-CONFIG_IP_NF_MANGLE=m | |
-CONFIG_IP_NF_TARGET_CLUSTERIP=m | |
-CONFIG_IP_NF_TARGET_ECN=m | |
-CONFIG_IP_NF_TARGET_TTL=m | |
+CONFIG_IP_NF_IPTABLES=y | |
+CONFIG_IP_NF_MATCH_AH=y | |
+CONFIG_IP_NF_MATCH_ECN=y | |
+CONFIG_IP_NF_MATCH_RPFILTER=y | |
+CONFIG_IP_NF_MATCH_TTL=y | |
+CONFIG_IP_NF_FILTER=y | |
+CONFIG_IP_NF_TARGET_REJECT=y | |
+CONFIG_IP_NF_TARGET_SYNPROXY=y | |
+CONFIG_IP_NF_NAT=y | |
+CONFIG_IP_NF_TARGET_MASQUERADE=y | |
+CONFIG_IP_NF_TARGET_NETMAP=y | |
+CONFIG_IP_NF_TARGET_REDIRECT=y | |
+CONFIG_IP_NF_MANGLE=y | |
+CONFIG_IP_NF_TARGET_CLUSTERIP=y | |
+CONFIG_IP_NF_TARGET_ECN=y | |
+CONFIG_IP_NF_TARGET_TTL=y | |
# CONFIG_IP_NF_RAW is not set | |
-CONFIG_IP_NF_SECURITY=m | |
+CONFIG_IP_NF_SECURITY=y | |
CONFIG_IP_NF_ARPTABLES=y | |
CONFIG_IP_NF_ARPFILTER=y | |
CONFIG_IP_NF_ARP_MANGLE=y | |
@@ -1239,7 +1298,7 @@ | |
CONFIG_BRIDGE_EBT_LOG=y | |
CONFIG_BRIDGE_EBT_NFLOG=y | |
CONFIG_BPFILTER=y | |
-CONFIG_BPFILTER_UMH=m | |
+CONFIG_BPFILTER_UMH=y | |
CONFIG_IP_DCCP=y | |
CONFIG_INET_DCCP_DIAG=y | |
@@ -1261,7 +1320,7 @@ | |
# CONFIG_SCTP_DEFAULT_COOKIE_HMAC_SHA1 is not set | |
# CONFIG_SCTP_DEFAULT_COOKIE_HMAC_NONE is not set | |
CONFIG_SCTP_COOKIE_HMAC_MD5=y | |
-# CONFIG_SCTP_COOKIE_HMAC_SHA1 is not set | |
+CONFIG_SCTP_COOKIE_HMAC_SHA1=y | |
CONFIG_INET_SCTP_DIAG=y | |
CONFIG_RDS=y | |
CONFIG_RDS_TCP=y | |
@@ -1279,14 +1338,16 @@ | |
CONFIG_L2TP=y | |
# CONFIG_L2TP_V3 is not set | |
CONFIG_STP=y | |
+CONFIG_GARP=y | |
+CONFIG_MRP=y | |
CONFIG_BRIDGE=y | |
CONFIG_BRIDGE_IGMP_SNOOPING=y | |
CONFIG_BRIDGE_VLAN_FILTERING=y | |
CONFIG_HAVE_NET_DSA=y | |
# CONFIG_NET_DSA is not set | |
CONFIG_VLAN_8021Q=y | |
-# CONFIG_VLAN_8021Q_GVRP is not set | |
-# CONFIG_VLAN_8021Q_MVRP is not set | |
+CONFIG_VLAN_8021Q_GVRP=y | |
+CONFIG_VLAN_8021Q_MVRP=y | |
# CONFIG_DECNET is not set | |
CONFIG_LLC=y | |
# CONFIG_LLC2 is not set |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment