Quellcode durchsuchen

Ping allowed only from whiteipsets

Edvinas Valatka vor 9 Jahren
Ursprung
Commit
2887cb2f1a
1 geänderte Dateien mit 1 neuen und 5 gelöschten Zeilen
  1. 1 5
      e-router

+ 1 - 5
e-router

@@ -88,6 +88,7 @@ setup_white() {
     done < $CONFD/WHITE.tcp
     iptables -A INPUT -p udp -i ${wan} -m set --match-set $whiteset src -m conntrack --ctstate NEW -j FW-FILTERED
     iptables -A INPUT -p tcp --syn -i ${wan} -m set --match-set $whiteset src -m conntrack --ctstate NEW -j FW-FILTERED
+    iptables -A INPUT -i ${wan} -p icmp --icmp-type 8 -m conntrack --ctstate NEW -m set --match-set $whiteset src  -j ACCEPT
 }
 
 setup_open() {
@@ -111,10 +112,6 @@ setup_cast() {
     iptables -A INPUT -i ${wan} -j FW-CAST
 }
 
-setup_ping(){
-    iptables -A INPUT -p icmp --icmp-type 8 -m conntrack --ctstate NEW -j ACCEPT
-}
-
 main () {
     set_defaults
     setup_whitenets
@@ -125,7 +122,6 @@ main () {
     setup_white
     setup_open
     setup_cast
-    setup_ping
     setup_final
 }