More IPv6 fixes
parent
8dcd3cfe42
commit
ece001ddb5
|
@ -70,6 +70,9 @@ IPV6BLOCKINCOMING=1
|
||||||
# Interface IPv6 comes in on (either tunnel or real network interface)
|
# Interface IPv6 comes in on (either tunnel or real network interface)
|
||||||
#IPV6INT=he-ipv6
|
#IPV6INT=he-ipv6
|
||||||
|
|
||||||
|
# LAN interface for IPv6
|
||||||
|
#IPV6LAN=eth1
|
||||||
|
|
||||||
# Trusted IPv6 ranges
|
# Trusted IPv6 ranges
|
||||||
IPV6TRUSTED="::1"
|
IPV6TRUSTED="::1"
|
||||||
|
|
||||||
|
|
|
@ -178,10 +178,10 @@ if [ $IPV6 ]; then
|
||||||
if [ $IPV6ROUTEDCLIENTBLOCK ]; then
|
if [ $IPV6ROUTEDCLIENTBLOCK ]; then
|
||||||
$IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
|
$IP6TABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
|
||||||
$IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
|
$IP6TABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
|
||||||
$IP6TABLES -A FORWARD -i $IPV6INT -p tcp --syn -j DROP
|
$IP6TABLES -A FORWARD -i $IPV6INT -o $IPV6LAN -p tcp --syn -j DROP
|
||||||
$IP6TABLES -A INPUT -i $IPV6INT -p tcp --syn -j DROP
|
$IP6TABLES -A INPUT -i $IPV6INT -o $IPV6LAN -p tcp --syn -j DROP
|
||||||
$IP6TABLES -A INPUT -i $IPV6INT -p udp ! --dport 32768:65535 -j DROP
|
$IP6TABLES -A INPUT -i $IPV6INT -o $IPV6LAN -p udp ! --dport 32768:65535 -j DROP
|
||||||
$IP6TABLES -A FORWARD -i $IPV6INT -p udp ! --dport 32768:65535 -j DROP
|
$IP6TABLES -A FORWARD -i $IPV6INT -o $IPV6LAN -p udp ! --dport 32768:65535 -j DROP
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echo -n "Adding allowed IPv6 port: "
|
echo -n "Adding allowed IPv6 port: "
|
||||||
|
|
Loading…
Reference in New Issue