X-Git-Url: http://git.ipfire.org/?p=people%2Fteissler%2Fipfire-2.x.git;a=blobdiff_plain;f=src%2Finitscripts%2Finit.d%2Ffirewall;h=cc6b6190eb8ecb7c376934b1aa74968915c46c6c;hp=9a4e5eb17b877a571e573709a8fc8f3b02936f74;hb=31901da1edb401590960558b61e31ddd9fda89c1;hpb=98dd8fc1a3a295e9e005bf15e51af578932ec95c diff --git a/src/initscripts/init.d/firewall b/src/initscripts/init.d/firewall index 9a4e5eb17..cc6b6190e 100644 --- a/src/initscripts/init.d/firewall +++ b/src/initscripts/init.d/firewall @@ -53,6 +53,9 @@ iptables_init() { # Chain to contain all the rules relating to bad TCP flags /sbin/iptables -N BADTCP + #Don't check loopback + /sbin/iptables -A BADTCP -i lo -j RETURN + # Disallow packets frequently used by port-scanners # nmap xmas /sbin/iptables -A BADTCP -p tcp --tcp-flags ALL FIN,URG,PSH -j PSCAN @@ -185,10 +188,9 @@ case "$1" in # Outgoing Firewall /sbin/iptables -A FORWARD -j OUTGOINGFWMAC - /sbin/iptables -A FORWARD -j OUTGOINGFW # localhost and ethernet. - /sbin/iptables -I INPUT 1 -i lo -m state --state NEW -j ACCEPT + /sbin/iptables -A INPUT -i lo -m state --state NEW -j ACCEPT /sbin/iptables -A INPUT -s 127.0.0.0/8 -m state --state NEW -j DROP # Loopback not on lo /sbin/iptables -A INPUT -d 127.0.0.0/8 -m state --state NEW -j DROP /sbin/iptables -A FORWARD -i lo -m state --state NEW -j ACCEPT @@ -250,6 +252,7 @@ case "$1" in # upnp chain for our upnp daemon /sbin/iptables -t nat -N UPNPFW /sbin/iptables -t nat -A PREROUTING -j UPNPFW + /sbin/iptables -A FORWARD -m state --state NEW -j UPNPFW # This chain only contains dummy rules. /sbin/iptables -N UPNPFW @@ -333,7 +336,9 @@ case "$1" in ;; restart) $0 stop + $0 stopovpn $0 start + $0 startovpn ;; *) echo "Usage: $0 {start|stop|reload|restart}"