|
@@ -1,13 +1,11 @@
|
|
#!/bin/sh
|
|
#!/bin/sh
|
|
-
|
|
|
|
-
|
|
|
|
echo "configure /etc/firewall.conf first."
|
|
echo "configure /etc/firewall.conf first."
|
|
exit 1
|
|
exit 1
|
|
|
|
|
|
### Interfaces
|
|
### Interfaces
|
|
WAN=ppp0
|
|
WAN=ppp0
|
|
LAN=br0
|
|
LAN=br0
|
|
-WLAN=
|
|
|
|
|
|
+WLAN=wlan0
|
|
|
|
|
|
######################################################################
|
|
######################################################################
|
|
### Default ruleset
|
|
### Default ruleset
|
|
@@ -29,7 +27,7 @@ iptables -P FORWARD DROP
|
|
# base case
|
|
# base case
|
|
iptables -A INPUT -m state --state INVALID -j DROP
|
|
iptables -A INPUT -m state --state INVALID -j DROP
|
|
iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
|
|
iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
|
|
-iptables -A INPUT -p tcp --tcp-flags SYN SYN --tcp-option \! 2 -j DROP
|
|
|
|
|
|
+iptables -A INPUT -p tcp --tcp-flags SYN SYN \! --tcp-option 2 -j DROP
|
|
|
|
|
|
# custom rules
|
|
# custom rules
|
|
iptables -A INPUT -j input_rule
|
|
iptables -A INPUT -j input_rule
|