From afd6539a653f4127d816f225b9b793fccb848ff2 Mon Sep 17 00:00:00 2001
From: Felix Fietkau <nbd@openwrt.org>
Date: Sun, 15 Oct 2006 23:04:23 +0000
Subject: [PATCH] add firewall protection for wan_device in addition to
 wan_ifname (fixes #852)

SVN-Revision: 5136
---
 package/iptables/files/firewall.init | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/package/iptables/files/firewall.init b/package/iptables/files/firewall.init
index 1e39d05fd9..4e8317d662 100755
--- a/package/iptables/files/firewall.init
+++ b/package/iptables/files/firewall.init
@@ -8,6 +8,7 @@ start() {
 	scan_interfaces
 	
 	config_get WAN wan ifname
+	config_get WANDEV wan device
 	config_get LAN lan ifname
 	
 	## CLEAR TABLES
@@ -25,6 +26,7 @@ start() {
 	
 	iptables -N LAN_ACCEPT
 	[ -z "$WAN" ] || iptables -A LAN_ACCEPT -i "$WAN" -j RETURN
+	[ -z "$WANDEV" -o "$WANDEV" = "$WAN" ] || iptables -A LAN_ACCEPT -i "$WANDEV" -j RETURN
 	iptables -A LAN_ACCEPT -j ACCEPT
 	
 	### INPUT
-- 
2.30.2