X-Git-Url: http://git.squeep.com/?p=firewall-squeep;a=blobdiff_plain;f=firewall.sh;fp=firewall.sh;h=145ee596f86c66d0d35b20feb5c2f1454f03e59e;hp=356075c424f98eb5d40a071a543455ba17a018a1;hb=468137e91e328a5603aafd9dea23ff096851fe38;hpb=3d7987337f881e38e8537233959c78054147e737 diff --git a/firewall.sh b/firewall.sh index 356075c..145ee59 100755 --- a/firewall.sh +++ b/firewall.sh @@ -71,25 +71,7 @@ do $IPTABLES -A INPUT -p tcp --tcp-flags ${flags} -j DROP done -create_set allowed_udp bitmap:port range 0-65535 -create_set allowed_tcp bitmap:port range 0-65535 - -for sfx in '' ".$(hostname -s)" -do - if [ -e "services${sfx}" ] - then - - for l in $(decommentcat "services${sfx}") - do - allow_services "${l}" - done - fi -done - -$IPTABLES -A INPUT -i "${EXT_IF}" -p tcp -m set --match-set allowed_tcp dst -j ACCEPT -$IPTABLES -A INPUT -i "${EXT_IF}" -p udp -m set --match-set allowed_udp dst -j ACCEPT -$IP6TABLES -A INPUT -i "${EXT_IF}" -p tcp -m set --match-set allowed_tcp dst -j ACCEPT -$IP6TABLES -A INPUT -i "${EXT_IF}" -p udp -m set --match-set allowed_udp dst -j ACCEPT +./services ${EXT_IF} create_drop_chain xenophobe