fix firewall rules
This commit is contained in:
@@ -1,6 +1,6 @@
|
|||||||
{ ... }: {
|
{ ... }: {
|
||||||
networking = {
|
networking = {
|
||||||
nat.enable = false;
|
nat.enable = true;
|
||||||
firewall = {
|
firewall = {
|
||||||
enable = true;
|
enable = true;
|
||||||
extraCommands = ''
|
extraCommands = ''
|
||||||
@@ -8,16 +8,16 @@
|
|||||||
iptables -A INPUT -i wan -j ACCEPT
|
iptables -A INPUT -i wan -j ACCEPT
|
||||||
iptables -A INPUT -i lan -j ACCEPT
|
iptables -A INPUT -i lan -j ACCEPT
|
||||||
iptables -A INPUT -i wg_cloonar -j ACCEPT
|
iptables -A INPUT -i wg_cloonar -j ACCEPT
|
||||||
iptables -A INPUT -p udp -i smart --dports 53,67,68 -j ACCEPT
|
iptables -A INPUT -p udp -i smart -m multiport --dports 53,67,68 -j ACCEPT
|
||||||
iptables -A INPUT -p udp -i multimedia --dports 53,67,68 -j ACCEPT
|
iptables -A INPUT -p udp -i multimedia -m multiport --dports 53,67,68 -j ACCEPT
|
||||||
iptables -A INPUT -p tcp -i smart --dports 80,443,453 -j ACCEPT
|
iptables -A INPUT -p tcp -i smart -m multiport --dports 80,443,453 -j ACCEPT
|
||||||
iptables -A INPUT -p tcp -i multimedia --dports 80,443,453 -j ACCEPT
|
iptables -A INPUT -p tcp -i multimedia -m multiport --dports 80,443,453 -j ACCEPT
|
||||||
|
|
||||||
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
||||||
|
|
||||||
iptables -A FORWARD -i wan -d 10.42.0.0/24 -j ACCEPT
|
iptables -A FORWARD -i wan -d 10.42.0.0/16 -j ACCEPT
|
||||||
iptables -A FORWARD -i lan -d 10.42.0.0/24 -j ACCEPT
|
iptables -A FORWARD -i lan -d 10.42.0.0/16 -j ACCEPT
|
||||||
iptables -A FORWARD -i wg_cloonar -d 10.42.0.0/24 -j ACCEPT
|
iptables -A FORWARD -i wg_cloonar -d 10.42.0.0/16 -j ACCEPT
|
||||||
|
|
||||||
iptables -A FORWARD -i lan -o wan -j ACCEPT
|
iptables -A FORWARD -i lan -o wan -j ACCEPT
|
||||||
iptables -A FORWARD -i server -o wan -j ACCEPT
|
iptables -A FORWARD -i server -o wan -j ACCEPT
|
||||||
|
|||||||
Reference in New Issue
Block a user