strongswan creates rules in iptables which are being dropped when the firewall is being restarted.
Signed-off-by: Michael Tremer michael.tremer@ipfire.org --- src/scripts/convert-to-location | 5 +++++ 1 file changed, 5 insertions(+)
diff --git a/src/scripts/convert-to-location b/src/scripts/convert-to-location index 9149b854d..428a91d34 100755 --- a/src/scripts/convert-to-location +++ b/src/scripts/convert-to-location @@ -47,6 +47,11 @@ if [ -f "$FW_CONF_DIR/geoipblock" ]; then
# Regenerate firewall chains. /etc/init.d/firewall restart + + # Restart IPsec for dropped iptables rules + if grep -q "ENABLED=on" /var/ipfire/vpn/settings; then + /etc/init.d/ipsec restart + fi fi
# Finished.