Forward Firewall: rules for collectd now in firewall-policy instead of /etc/init.d/firewall

This commit is contained in:
Alexander Marx
2013-04-15 20:29:15 +02:00
committed by Michael Tremer
parent 53f4c74d9b
commit aff15defbc
2 changed files with 4 additions and 10 deletions

View File

@@ -31,6 +31,7 @@ else
/sbin/iptables -A POLICYFWD -i blue0 ! -o $IFACE -j DROP /sbin/iptables -A POLICYFWD -i blue0 ! -o $IFACE -j DROP
fi fi
/sbin/iptables -A POLICYFWD -j ACCEPT /sbin/iptables -A POLICYFWD -j ACCEPT
/sbin/iptables -A POLICYFWD -m comment --comment "DROP_FORWARD" -j DROP
fi fi
#OUTGOINGFW #OUTGOINGFW
@@ -49,6 +50,7 @@ if [ "$POLICY1" == "MODE1" ]; then
fi fi
else else
/sbin/iptables -A POLICYOUT -j ACCEPT /sbin/iptables -A POLICYOUT -j ACCEPT
/sbin/iptables -A POLICYOUT -m comment --comment "DROP_OUTPUT" -j DROP
fi fi
#INPUT #INPUT
if [ "$FWPOLICY2" == "REJECT" ]; then if [ "$FWPOLICY2" == "REJECT" ]; then
@@ -63,3 +65,5 @@ if [ "$FWPOLICY2" == "DROP" ]; then
fi fi
/sbin/iptables -A POLICYIN -j DROP -m comment --comment "DROP_INPUT" /sbin/iptables -A POLICYIN -j DROP -m comment --comment "DROP_INPUT"
fi fi
exit 0

View File

@@ -276,10 +276,6 @@ case "$1" in
/sbin/iptables -A OUTPUT -j POLICYOUT /sbin/iptables -A OUTPUT -j POLICYOUT
/usr/sbin/firewall-policy /usr/sbin/firewall-policy
#Only for firewall Hits statistik
/sbin/iptables -A POLICYFWD -j DROP -m comment --comment "DROP_FORWARD"
/sbin/iptables -A POLICYOUT -j DROP -m comment --comment "DROP_OUTPUT"
;; ;;
startovpn) startovpn)
# run openvpn # run openvpn
@@ -317,12 +313,6 @@ case "$1" in
fi fi
/sbin/iptables -A FORWARD -j DROP -m comment --comment "DROP_FORWARD" /sbin/iptables -A FORWARD -j DROP -m comment --comment "DROP_FORWARD"
#Only for firewall Hits statistik
#/sbin/iptables -A POLICYFWD -j DROP -m comment --comment "DROP_FORWARD"
#/sbin/iptables -A POLICYOUT -j DROP -m comment --comment "DROP_OUTPUT"
;; ;;
stopovpn) stopovpn)
# stop openvpn # stop openvpn