home
·
contact
·
privacy
projects
/
config
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
Fix.
[config]
/
all_new_2018
/
linkable_etc_files
/
server
/
etc
/
iptables
/
rules.v4
diff --git
a/all_new_2018/linkable_etc_files/server/etc/iptables/rules.v4
b/all_new_2018/linkable_etc_files/server/etc/iptables/rules.v4
index 01dca753763dc25509bc048a947eb2c9a3f59a08..8e0b1f6914be55c4a6e551b7f088a29f26579c81 100644
(file)
--- a/
all_new_2018/linkable_etc_files/server/etc/iptables/rules.v4
+++ b/
all_new_2018/linkable_etc_files/server/etc/iptables/rules.v4
@@
-2,11
+2,13
@@
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]
+# otherwise self-referential connections to local host will fail
-A INPUT -i lo -j ACCEPT
-A INPUT -i lo -j ACCEPT
+# tolerate any inbound connections requested by our server, no matter the port
+-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
+# this enables ping etc.
-A INPUT -p icmp -j ACCEPT
-A INPUT -p icmp -j ACCEPT
+# SSH
-A INPUT -p tcp --dport 22 -j ACCEPT
-A INPUT -p tcp --dport 22 -j ACCEPT
--A INPUT -p tcp --dport 443 -j ACCEPT
--A INPUT -p tcp --dport 80 -j ACCEPT
--A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
COMMIT
COMMIT
-#
iptables-restore seems to ignore COMMIT
if no newline follows it
\ No newline at end of file
+#
this last line is here because iptables-restore ignores the final command
if no newline follows it
\ No newline at end of file