More...
This commit is contained in:
		
							parent
							
								
									c8b0a5d109
								
							
						
					
					
						commit
						4578afcb52
					
				
							
								
								
									
										20
									
								
								rc.firewall
									
									
									
									
									
								
							
							
						
						
									
										20
									
								
								rc.firewall
									
									
									
									
									
								
							@ -175,15 +175,6 @@ if [ $IPV6 ]; then
 | 
				
			|||||||
	done
 | 
						done
 | 
				
			||||||
	echo -ne "\n"
 | 
						echo -ne "\n"
 | 
				
			||||||
 | 
					
 | 
				
			||||||
	if [ $IPV6ROUTEDCLIENTBLOCK ]; then
 | 
					 | 
				
			||||||
		$IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
 | 
					 | 
				
			||||||
		$IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
 | 
					 | 
				
			||||||
		$IP6TABLES -A FORWARD -i $IPV6INT -o $IPV6LAN -p tcp --syn -j DROP
 | 
					 | 
				
			||||||
		$IP6TABLES -A INPUT -i $IPV6INT -p tcp --syn -j DROP
 | 
					 | 
				
			||||||
		$IP6TABLES -A INPUT -i $IPV6INT -p udp ! --dport 32768:65535 -j DROP
 | 
					 | 
				
			||||||
		$IP6TABLES -A FORWARD -i $IPV6INT -o $IPV6LAN -p udp ! --dport 32768:65535 -j DROP
 | 
					 | 
				
			||||||
	fi
 | 
					 | 
				
			||||||
	
 | 
					 | 
				
			||||||
	echo -n "Adding allowed IPv6 port: "
 | 
						echo -n "Adding allowed IPv6 port: "
 | 
				
			||||||
 | 
					
 | 
				
			||||||
	for i in $IPV6TCP; do
 | 
						for i in $IPV6TCP; do
 | 
				
			||||||
@ -199,6 +190,17 @@ if [ $IPV6 ]; then
 | 
				
			|||||||
	done
 | 
						done
 | 
				
			||||||
	echo -en "\n"
 | 
						echo -en "\n"
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
						if [ $IPV6ROUTEDCLIENTBLOCK ]; then
 | 
				
			||||||
 | 
							$IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
 | 
				
			||||||
 | 
							$IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
 | 
				
			||||||
 | 
							$IP6TABLES -A FORWARD -i $IPV6INT -o $IPV6LAN -p tcp --syn -j DROP
 | 
				
			||||||
 | 
							$IP6TABLES -A INPUT -i $IPV6INT -p tcp --syn -j DROP
 | 
				
			||||||
 | 
							$IP6TABLES -A INPUT -i $IPV6INT -p udp ! --dport 32768:65535 -j DROP
 | 
				
			||||||
 | 
							$IP6TABLES -A FORWARD -i $IPV6INT -o $IPV6LAN -p udp ! --dport 32768:65535 -j DROP
 | 
				
			||||||
 | 
						fi
 | 
				
			||||||
 | 
						
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					
 | 
				
			||||||
	if [ $IPV6FORWARDRANGE ]; then
 | 
						if [ $IPV6FORWARDRANGE ]; then
 | 
				
			||||||
		for i in $IPV6FORWARDRANGE; do
 | 
							for i in $IPV6FORWARDRANGE; do
 | 
				
			||||||
			$IP6TABLES -A FORWARD -s $i -j ACCEPT
 | 
								$IP6TABLES -A FORWARD -s $i -j ACCEPT
 | 
				
			||||||
 | 
				
			|||||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user