diff --git a/src/initscripts/system/firewall b/src/initscripts/system/firewall index 424852a01..2a8877d20 100644 --- a/src/initscripts/system/firewall +++ b/src/initscripts/system/firewall @@ -216,6 +216,11 @@ iptables_init() { iptables -A FORWARD -m policy --dir out --pol none -j IPSECBLOCK iptables -A OUTPUT -m policy --dir out --pol none -j IPSECBLOCK + # Block unauthorized WireGuard traffic + ipatbles -N WGBLOCK + iptables -A INPUT -i wg+ -j WGBLOCK + iptables -A FORWARD -i wg+ -j WGBLOCK + # Block OpenVPN transfer networks iptables -N OVPNBLOCK iptables -A INPUT -i tun+ -j OVPNBLOCK