mirror of https://github.com/aredn/aredn.git
Merge branch 'VtunFirewall' into release-3.15.1.0
This commit is contained in:
commit
5a9ec7bf63
|
@ -31,9 +31,9 @@ if [ $rules_exist -eq 0 -a "$action" = "up" ] ; then
|
||||||
iptables -N zone_vpn_DROP
|
iptables -N zone_vpn_DROP
|
||||||
iptables -N zone_vpn_REJECT
|
iptables -N zone_vpn_REJECT
|
||||||
iptables -N zone_vpn_forward
|
iptables -N zone_vpn_forward
|
||||||
iptables -A forward -i tun+ -j zone_vpn_forward
|
iptables -I delegate_forward 3 -i tun+ -j zone_vpn_forward
|
||||||
iptables -A input -i tun+ -j zone_vpn
|
iptables -I delegate_input 3 -i tun+ -j zone_vpn
|
||||||
iptables -A output -j zone_vpn_ACCEPT
|
iptables -I delegate_output 3 -j zone_vpn_ACCEPT
|
||||||
iptables -A zone_vpn -p icmp -m icmp --icmp-type 8 -j ACCEPT
|
iptables -A zone_vpn -p icmp -m icmp --icmp-type 8 -j ACCEPT
|
||||||
iptables -A zone_vpn -p tcp -m tcp --dport 2222 -j ACCEPT
|
iptables -A zone_vpn -p tcp -m tcp --dport 2222 -j ACCEPT
|
||||||
iptables -A zone_vpn -p tcp -m tcp --dport 8080 -j ACCEPT
|
iptables -A zone_vpn -p tcp -m tcp --dport 8080 -j ACCEPT
|
||||||
|
@ -92,9 +92,9 @@ if [ $inf_count -eq 0 -a "$action" = "down" ] ; then
|
||||||
iptables -D zone_vpn -p tcp -m tcp --dport 8080 -j ACCEPT
|
iptables -D zone_vpn -p tcp -m tcp --dport 8080 -j ACCEPT
|
||||||
iptables -D zone_vpn -p tcp -m tcp --dport 2222 -j ACCEPT
|
iptables -D zone_vpn -p tcp -m tcp --dport 2222 -j ACCEPT
|
||||||
iptables -D zone_vpn -p icmp -m icmp --icmp-type 8 -j ACCEPT
|
iptables -D zone_vpn -p icmp -m icmp --icmp-type 8 -j ACCEPT
|
||||||
iptables -D output -j zone_vpn_ACCEPT
|
iptables -D delegate_output -j zone_vpn_ACCEPT
|
||||||
iptables -D input -i tun+ -j zone_vpn
|
iptables -D delegate_input -i tun+ -j zone_vpn
|
||||||
iptables -D forward -i tun+ -j zone_vpn_forward
|
iptables -D delegate_forward -i tun+ -j zone_vpn_forward
|
||||||
iptables -X zone_vpn_REJECT
|
iptables -X zone_vpn_REJECT
|
||||||
iptables -X zone_vpn_DROP
|
iptables -X zone_vpn_DROP
|
||||||
iptables -X zone_vpn_ACCEPT
|
iptables -X zone_vpn_ACCEPT
|
||||||
|
|
Loading…
Reference in New Issue