cni icon indicating copy to clipboard operation
cni copied to clipboard

Add an iptables rule to drop packets that conntrack considers invalid.

Open mccv1r0 opened this issue 2 years ago • 1 comments

Add an iptables rule to drop packets that conntrack considers invalid.

One rule for the life of CNI vs one for ipMasq, portmap etc.

This is an alternative to adding an unique container IP specific rules every cniADD for ipMasq, portmap and then removing when cniDel is called.

Fixes plugins 816

Signed-off-by: Michael Cambria [email protected]

mccv1r0 avatar Jan 30 '23 18:01 mccv1r0