mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-04-27 19:23:24 +02:00
Forward Firewall: rules for collectd now in firewall-policy instead of /etc/init.d/firewall
This commit is contained in:
committed by
Michael Tremer
parent
53f4c74d9b
commit
aff15defbc
@@ -31,6 +31,7 @@ else
|
|||||||
/sbin/iptables -A POLICYFWD -i blue0 ! -o $IFACE -j DROP
|
/sbin/iptables -A POLICYFWD -i blue0 ! -o $IFACE -j DROP
|
||||||
fi
|
fi
|
||||||
/sbin/iptables -A POLICYFWD -j ACCEPT
|
/sbin/iptables -A POLICYFWD -j ACCEPT
|
||||||
|
/sbin/iptables -A POLICYFWD -m comment --comment "DROP_FORWARD" -j DROP
|
||||||
fi
|
fi
|
||||||
|
|
||||||
#OUTGOINGFW
|
#OUTGOINGFW
|
||||||
@@ -49,6 +50,7 @@ if [ "$POLICY1" == "MODE1" ]; then
|
|||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
/sbin/iptables -A POLICYOUT -j ACCEPT
|
/sbin/iptables -A POLICYOUT -j ACCEPT
|
||||||
|
/sbin/iptables -A POLICYOUT -m comment --comment "DROP_OUTPUT" -j DROP
|
||||||
fi
|
fi
|
||||||
#INPUT
|
#INPUT
|
||||||
if [ "$FWPOLICY2" == "REJECT" ]; then
|
if [ "$FWPOLICY2" == "REJECT" ]; then
|
||||||
@@ -63,3 +65,5 @@ if [ "$FWPOLICY2" == "DROP" ]; then
|
|||||||
fi
|
fi
|
||||||
/sbin/iptables -A POLICYIN -j DROP -m comment --comment "DROP_INPUT"
|
/sbin/iptables -A POLICYIN -j DROP -m comment --comment "DROP_INPUT"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
exit 0
|
||||||
|
|||||||
@@ -276,10 +276,6 @@ case "$1" in
|
|||||||
/sbin/iptables -A OUTPUT -j POLICYOUT
|
/sbin/iptables -A OUTPUT -j POLICYOUT
|
||||||
|
|
||||||
/usr/sbin/firewall-policy
|
/usr/sbin/firewall-policy
|
||||||
|
|
||||||
#Only for firewall Hits statistik
|
|
||||||
/sbin/iptables -A POLICYFWD -j DROP -m comment --comment "DROP_FORWARD"
|
|
||||||
/sbin/iptables -A POLICYOUT -j DROP -m comment --comment "DROP_OUTPUT"
|
|
||||||
;;
|
;;
|
||||||
startovpn)
|
startovpn)
|
||||||
# run openvpn
|
# run openvpn
|
||||||
@@ -317,12 +313,6 @@ case "$1" in
|
|||||||
fi
|
fi
|
||||||
/sbin/iptables -A FORWARD -j DROP -m comment --comment "DROP_FORWARD"
|
/sbin/iptables -A FORWARD -j DROP -m comment --comment "DROP_FORWARD"
|
||||||
|
|
||||||
#Only for firewall Hits statistik
|
|
||||||
#/sbin/iptables -A POLICYFWD -j DROP -m comment --comment "DROP_FORWARD"
|
|
||||||
#/sbin/iptables -A POLICYOUT -j DROP -m comment --comment "DROP_OUTPUT"
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
;;
|
;;
|
||||||
stopovpn)
|
stopovpn)
|
||||||
# stop openvpn
|
# stop openvpn
|
||||||
|
|||||||
Reference in New Issue
Block a user