More IPv6 fixes
This commit is contained in:
		
							parent
							
								
									8dcd3cfe42
								
							
						
					
					
						commit
						ece001ddb5
					
				@ -70,6 +70,9 @@ IPV6BLOCKINCOMING=1
 | 
			
		||||
# Interface IPv6 comes in on (either tunnel or real network interface)
 | 
			
		||||
#IPV6INT=he-ipv6
 | 
			
		||||
 | 
			
		||||
# LAN interface for IPv6
 | 
			
		||||
#IPV6LAN=eth1
 | 
			
		||||
 | 
			
		||||
# Trusted IPv6 ranges
 | 
			
		||||
IPV6TRUSTED="::1"
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
@ -178,10 +178,10 @@ if [ $IPV6 ]; then
 | 
			
		||||
	if [ $IPV6ROUTEDCLIENTBLOCK ]; then
 | 
			
		||||
		$IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
 | 
			
		||||
		$IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
 | 
			
		||||
		$IP6TABLES -A FORWARD -i $IPV6INT -p tcp --syn -j DROP
 | 
			
		||||
		$IP6TABLES -A INPUT -i $IPV6INT -p tcp --syn -j DROP
 | 
			
		||||
		$IP6TABLES -A INPUT -i $IPV6INT -p udp ! --dport 32768:65535 -j DROP
 | 
			
		||||
		$IP6TABLES -A FORWARD -i $IPV6INT -p udp ! --dport 32768:65535 -j DROP
 | 
			
		||||
		$IP6TABLES -A FORWARD -i $IPV6INT -o $IPV6LAN -p tcp --syn -j DROP
 | 
			
		||||
		$IP6TABLES -A INPUT -i $IPV6INT -o $IPV6LAN -p tcp --syn -j DROP
 | 
			
		||||
		$IP6TABLES -A INPUT -i $IPV6INT -o $IPV6LAN -p udp ! --dport 32768:65535 -j DROP
 | 
			
		||||
		$IP6TABLES -A FORWARD -i $IPV6INT -o $IPV6LAN -p udp ! --dport 32768:65535 -j DROP
 | 
			
		||||
	fi
 | 
			
		||||
	
 | 
			
		||||
	echo -n "Adding allowed IPv6 port: "
 | 
			
		||||
 | 
			
		||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user