X-Git-Url: http://git.squeep.com/?a=blobdiff_plain;f=firewall.sh;h=145ee596f86c66d0d35b20feb5c2f1454f03e59e;hb=468137e91e328a5603aafd9dea23ff096851fe38;hp=dbc0c3f47328828a09938e1083c0ff1fdfcaa41e;hpb=eb51f872880078e26facd139d9bd16e8640ce4a9;p=firewall-squeep diff --git a/firewall.sh b/firewall.sh index dbc0c3f..145ee59 100755 --- a/firewall.sh +++ b/firewall.sh @@ -71,25 +71,12 @@ do $IPTABLES -A INPUT -p tcp --tcp-flags ${flags} -j DROP done -create_set allowed_udp bitmap:port range 0-65535 -create_set allowed_tcp bitmap:port range 0-65535 +./services ${EXT_IF} -for sfx in '' ".$(hostname -s)" -do - if [ -e "services${sfx}" ] - then - - for l in $(decommentcat "services${sfx}") - do - allow_services "${l}" - done - fi -done +create_drop_chain xenophobe -$IPTABLES -A INPUT -i "${EXT_IF}" -p tcp -m set --match-set allowed_tcp dst -j ACCEPT -$IPTABLES -A INPUT -i "${EXT_IF}" -p udp -m set --match-set allowed_udp dst -j ACCEPT -$IP6TABLES -A INPUT -i "${EXT_IF}" -p tcp -m set --match-set allowed_tcp dst -j ACCEPT -$IP6TABLES -A INPUT -i "${EXT_IF}" -p udp -m set --match-set allowed_udp dst -j ACCEPT +# insert asia blocker +./sinokorea.sh # insert persistent-pest-blocker ./xenophobe.sh