More IPv6 fixes
parent
8dcd3cfe42
commit
ece001ddb5
|
@ -70,6 +70,9 @@ IPV6BLOCKINCOMING=1
|
|||
# Interface IPv6 comes in on (either tunnel or real network interface)
|
||||
#IPV6INT=he-ipv6
|
||||
|
||||
# LAN interface for IPv6
|
||||
#IPV6LAN=eth1
|
||||
|
||||
# Trusted IPv6 ranges
|
||||
IPV6TRUSTED="::1"
|
||||
|
||||
|
|
|
@ -178,10 +178,10 @@ if [ $IPV6 ]; then
|
|||
if [ $IPV6ROUTEDCLIENTBLOCK ]; then
|
||||
$IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
|
||||
$IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
|
||||
$IP6TABLES -A FORWARD -i $IPV6INT -p tcp --syn -j DROP
|
||||
$IP6TABLES -A INPUT -i $IPV6INT -p tcp --syn -j DROP
|
||||
$IP6TABLES -A INPUT -i $IPV6INT -p udp ! --dport 32768:65535 -j DROP
|
||||
$IP6TABLES -A FORWARD -i $IPV6INT -p udp ! --dport 32768:65535 -j DROP
|
||||
$IP6TABLES -A FORWARD -i $IPV6INT -o $IPV6LAN -p tcp --syn -j DROP
|
||||
$IP6TABLES -A INPUT -i $IPV6INT -o $IPV6LAN -p tcp --syn -j DROP
|
||||
$IP6TABLES -A INPUT -i $IPV6INT -o $IPV6LAN -p udp ! --dport 32768:65535 -j DROP
|
||||
$IP6TABLES -A FORWARD -i $IPV6INT -o $IPV6LAN -p udp ! --dport 32768:65535 -j DROP
|
||||
fi
|
||||
|
||||
echo -n "Adding allowed IPv6 port: "
|
||||
|
|
Loading…
Reference in New Issue