Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update iptables_rules.json #1650

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Update iptables_rules.json
updated firewall rules for openvpn and wireguard to stop packet leakage if either tunnel abends.
  • Loading branch information
frankozland authored Aug 24, 2024
commit c6520d99e9dc1987fd2ceabd4fc1aad43f79efd9
24 changes: 17 additions & 7 deletions config/iptables_rules.json
Original file line number Diff line number Diff line change
Expand Up @@ -117,11 +117,16 @@
{ "var": "ap-device", "type": "string", "replace": "$INTERFACE$" }
],
"rules": [
"-A INPUT -p udp -s $IPADDRESS$ -j ACCEPT",
"-A FORWARD -i tun+ -o $INTERFACE$ -m state --state RELATED,ESTABLISHED -j ACCEPT",
"-A FORWARD -i $INTERFACE$ -o tun+ -j ACCEPT",
"-t nat -A POSTROUTING -o tun+ -j MASQUERADE"
]
"-A INPUT -s $IPADDRESS$ -j ACCEPT",
"-A FORWARD -i tun+ -o wlan+ -j ACCEPT",
"-A FORWARD -i tun+ -o tun+ -j DROP",
"-A FORWARD -i wlan+ -o tun+ -j ACCEPT",
"-A FORWARD -i eth+ -o tun+ -j ACCEPT",
"-A FORWARD -i tun+ -o eth+ -j ACCEPT",
"-t nat -A POSTROUTING -o $INTERFACE$ -j MASQUERADE",
"-P FORWARD DROP"
]

},
{
"name": "wireguard",
Expand All @@ -134,8 +139,13 @@
],
"rules": [
"-A INPUT -p udp -s $IPADDRESS$ -j ACCEPT",
"-A FORWARD -i wg+ -j ACCEPT",
"-t nat -A POSTROUTING -o $INTERFACE$ -j MASQUERADE"
"-A FORWARD -i wg+ -o wlan+ -j ACCEPT",
"-A FORWARD -i wg+ -o wg+ -j DROP",
"-A FORWARD -i wlan+ -o wg+ -j ACCEPT",
"-A FORWARD -i eth+ -o wg+ -j ACCEPT",
"-A FORWARD -i wg+ -o eth+ -j ACCEPT",
"-t nat -A POSTROUTING -o $INTERFACE$ -j MASQUERADE",
"-P FORWARD DROP"
]
}
],
Expand Down