Diff for scripts/shell/firewall/fw-universal.sh between version 2.118 and 2.119
version 2.118, 2018/12/10 11:46:12 |
version 2.119, 2019/02/14 07:41:47 |
|
|
# Licensed under terms of GNU General Public License. |
# Licensed under terms of GNU General Public License. |
# All rights reserved. |
# All rights reserved. |
# |
# |
# $Platon: scripts/shell/firewall/fw-universal.sh,v 2.117 2018/08/23 04:34:58 nepto Exp $ |
# $Platon: scripts/shell/firewall/fw-universal.sh,v 2.118 2018/12/10 11:46:12 nepto Exp $ |
# |
# |
# Changelog: |
# Changelog: |
# 2003-10-24 - created |
# 2003-10-24 - created |
Line 816 allow_accept_all() |
|
Line 816 allow_accept_all() |
|
fi |
fi |
} # }}} |
} # }}} |
|
|
|
allow_accept_vrrp() |
|
{ # {{{ |
|
if [ ! -z "$IFACE_ACCEPT_VRRP" ]; then |
|
print_info -en "Accepting VRRP packets on interfaces:" |
|
for iface in $IFACE_ACCEPT_VRRP; do |
|
print_info -en " $iface" |
|
$IPTABLES -A INPUT -i $iface -d 224.0.0.18/32 -p vrrp -j ACCEPT; |
|
$IPTABLES -A OUTPUT -i $iface -d 224.0.0.18/32 -p vrrp -j ACCEPT; |
|
done |
|
print_info " done." |
|
fi |
|
} # }}} |
|
|
drop_input() |
drop_input() |
{ # {{{ |
{ # {{{ |
if [ ! -z "$NAT_LAN_IFACE" ]; then |
if [ ! -z "$NAT_LAN_IFACE" ]; then |
|
|
# |
# |
bann_ip_adresses |
bann_ip_adresses |
allow_accept_all |
allow_accept_all |
|
allow_accept_vrrp |
nmap_scan_filter |
nmap_scan_filter |
invalid_packet_filter |
invalid_packet_filter |
anti_spoof_filter |
anti_spoof_filter |
Platon Group <platon@platon.org> http://platon.org/
|
|