about summary refs log tree commit diff stats
diff options
context:
space:
mode:
authorSilvino <silvino@bk.ru>2019-06-28 03:54:24 +0100
committerSilvino <silvino@bk.ru>2019-06-28 03:54:24 +0100
commitb0c241f112e1e50a2910249cfe66c1648ba2f3fa (patch)
treeb3e2ece9fb9e741607102b3344a5bd768944d68f
parent8527dd081b4cdcca07e1477b742eaa2e1218f62f (diff)
downloaddoc-b0c241f112e1e50a2910249cfe66c1648ba2f3fa.tar.gz
core iptables bridge revision
-rw-r--r--core/conf/iptables/bridge.v435
-rw-r--r--core/conf/iptables/ipt-bridge.sh4
2 files changed, 22 insertions, 17 deletions
diff --git a/core/conf/iptables/bridge.v4 b/core/conf/iptables/bridge.v4
index 35bfef4..4930262 100644
--- a/core/conf/iptables/bridge.v4
+++ b/core/conf/iptables/bridge.v4
@@ -1,34 +1,34 @@
-# Generated by iptables-save v1.8.2 on Wed Jun 26 15:44:59 2019
+# Generated by iptables-save v1.8.2 on Fri Jun 28 01:22:10 2019
 *security
 :INPUT ACCEPT [0:0]
 :FORWARD ACCEPT [0:0]
 :OUTPUT ACCEPT [0:0]
 COMMIT
-# Completed on Wed Jun 26 15:44:59 2019
-# Generated by iptables-save v1.8.2 on Wed Jun 26 15:44:59 2019
+# Completed on Fri Jun 28 01:22:10 2019
+# Generated by iptables-save v1.8.2 on Fri Jun 28 01:22:10 2019
 *raw
-:PREROUTING ACCEPT [0:0]
-:OUTPUT ACCEPT [0:0]
+:PREROUTING ACCEPT [2:80]
+:OUTPUT ACCEPT [3:4544]
 COMMIT
-# Completed on Wed Jun 26 15:44:59 2019
-# Generated by iptables-save v1.8.2 on Wed Jun 26 15:44:59 2019
+# Completed on Fri Jun 28 01:22:10 2019
+# Generated by iptables-save v1.8.2 on Fri Jun 28 01:22:10 2019
 *nat
 :PREROUTING ACCEPT [0:0]
 :INPUT ACCEPT [0:0]
 :OUTPUT ACCEPT [0:0]
 :POSTROUTING ACCEPT [0:0]
 COMMIT
-# Completed on Wed Jun 26 15:44:59 2019
-# Generated by iptables-save v1.8.2 on Wed Jun 26 15:44:59 2019
+# Completed on Fri Jun 28 01:22:10 2019
+# Generated by iptables-save v1.8.2 on Fri Jun 28 01:22:10 2019
 *mangle
-:PREROUTING ACCEPT [0:0]
-:INPUT ACCEPT [0:0]
+:PREROUTING ACCEPT [2:80]
+:INPUT ACCEPT [2:80]
 :FORWARD ACCEPT [0:0]
-:OUTPUT ACCEPT [0:0]
-:POSTROUTING ACCEPT [0:0]
+:OUTPUT ACCEPT [3:4544]
+:POSTROUTING ACCEPT [2:2292]
 COMMIT
-# Completed on Wed Jun 26 15:44:59 2019
-# Generated by iptables-save v1.8.2 on Wed Jun 26 15:44:59 2019
+# Completed on Fri Jun 28 01:22:10 2019
+# Generated by iptables-save v1.8.2 on Fri Jun 28 01:22:10 2019
 *filter
 :INPUT DROP [0:0]
 :FORWARD DROP [0:0]
@@ -91,6 +91,9 @@ COMMIT
 -A FORWARD -d 10.0.0.4/32 -i br0 -o br0 -m physdev --physdev-in enp8s0 -j srv_ssh_in
 -A FORWARD -d 10.0.0.4/32 -i br0 -o br0 -m physdev --physdev-in enp8s0 -j srv_git_in
 -A FORWARD -i br0 -o br0 -p tcp -m physdev --physdev-in enp8s0 -m tcp --sport 443 --dport 1024:65535 -j ACCEPT
+-A FORWARD -d 10.0.0.3/32 -i br0 -o br0 -m physdev --physdev-in enp8s0 -j cli_http_in
+-A FORWARD -i br0 -o br0 -p udp -m udp --sport 520 --dport 519 -j DROP
+-A FORWARD -i br0 -o br0 -p udp -m udp --sport 520 --dport 520 -j DROP
 -A FORWARD -j LOG --log-prefix "iptables: FORWARD: " --log-level 7
 -A OUTPUT -s 127.0.0.0/8 -d 127.0.0.0/8 -o lo -j ACCEPT
 -A OUTPUT -s 10.0.0.254/32 -d 10.0.0.254/32 -o lo -j ACCEPT
@@ -217,4 +220,4 @@ COMMIT
 -A srv_ssh_out -p tcp -m tcp --sport 22 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT
 -A srv_ssh_out -j RETURN
 COMMIT
-# Completed on Wed Jun 26 15:44:59 2019
+# Completed on Fri Jun 28 01:22:10 2019
diff --git a/core/conf/iptables/ipt-bridge.sh b/core/conf/iptables/ipt-bridge.sh
index 6dbeb87..694c22f 100644
--- a/core/conf/iptables/ipt-bridge.sh
+++ b/core/conf/iptables/ipt-bridge.sh
@@ -50,8 +50,10 @@ $IPT -A FORWARD -i ${BR_IF} -o ${BR_IF} -m physdev --physdev-in ${PUB_IF} -d 10.
 $IPT -A FORWARD -i ${BR_IF} -o ${BR_IF} -m physdev --physdev-in ${PUB_IF} -d 10.0.0.4 -j srv_git_in
 $IPT -A FORWARD -i ${BR_IF} -o ${BR_IF} -m physdev --physdev-in ${PUB_IF} -p tcp --sport 443 --dport 1024:65535 -j ACCEPT
 
+$IPT -A FORWARD -i ${BR_IF} -o ${BR_IF} -m physdev --physdev-in ${PUB_IF} -d 10.0.0.3 -j cli_http_in
 ##Less noise
-#$IPT -A FORWARD -i ${BR_IF} -o ${BR_IF}  -p udp --dport 519 --sport 520 -j DROP
+$IPT -A FORWARD -i ${BR_IF} -o ${BR_IF}  -p udp --dport 519 --sport 520 -j DROP
+$IPT -A FORWARD -i ${BR_IF} -o ${BR_IF}  -p udp --dport 520 --sport 520 -j DROP
 
 ######## Input Chain ######
 $IPT -A INPUT -j blocker
Thomas E. Dickey <dickey@invisible-island.net> 1998-09-07 10:39:47 -0400 snapshot of project "lynx", label v2-8-1dev_25' href='/ingrix/lynx-snapshots/commit/src/chrtrans/cp1253_uni.tbl?id=5816641fc3a761e00d154c4dea9551a0027a7c63'>5816641f ^
51f21bae ^
e47cfd56 ^





51f21bae ^
e47cfd56 ^
51f21bae ^
e47cfd56 ^
51f21bae ^




e47cfd56 ^






51f21bae ^
e47cfd56 ^
51f21bae ^
e47cfd56 ^
51f21bae ^



e47cfd56 ^









51f21bae ^
e47cfd56 ^






































51f21bae ^
e47cfd56 ^











































51f21bae ^
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156