More fixes to NAT/Connection tracking
This commit is contained in:
		
							parent
							
								
									77b891f0a5
								
							
						
					
					
						commit
						aec794cddd
					
				
							
								
								
									
										10
									
								
								rc.firewall
									
									
									
									
									
								
							
							
						
						
									
										10
									
								
								rc.firewall
									
									
									
									
									
								
							@ -128,6 +128,16 @@ if [ $LANDHCPSERVER ]; then
 | 
			
		||||
	$IPTABLES -A INPUT -i $INTIF -s 0.0.0.0 -j ACCEPT
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
if [ $CONNTRACK ]; then
 | 
			
		||||
	$IPTABLES -A INPUT -i lo -m state --state NEW -j ACCEPT
 | 
			
		||||
	$IPTABLES -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
 | 
			
		||||
	$IPTABLES -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
 | 
			
		||||
	$IPTABLES -A INPUT -m state --state INVALID -j DROP
 | 
			
		||||
	$IPTABLES -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT 
 | 
			
		||||
	$IPTABLES -A OUTPUT -m state --state NEW -j ACCEPT
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
if [ $NAT ]; then
 | 
			
		||||
	for i in $NATRANGE; do
 | 
			
		||||
		$IPTABLES -A POSTROUTING -t nat -s $i -o $NATEXTIF -j SNAT --to-source $NATEXTIP
 | 
			
		||||
 | 
			
		||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user