summaryrefslogtreecommitdiff
path: root/roles/elevate/media/templates/firewall/lan-only.sh.j2
diff options
context:
space:
mode:
Diffstat (limited to 'roles/elevate/media/templates/firewall/lan-only.sh.j2')
-rw-r--r--roles/elevate/media/templates/firewall/lan-only.sh.j27
1 files changed, 4 insertions, 3 deletions
diff --git a/roles/elevate/media/templates/firewall/lan-only.sh.j2 b/roles/elevate/media/templates/firewall/lan-only.sh.j2
index 9a7db67a..aa9f03d8 100644
--- a/roles/elevate/media/templates/firewall/lan-only.sh.j2
+++ b/roles/elevate/media/templates/firewall/lan-only.sh.j2
@@ -28,6 +28,7 @@ ipv4_up() {
$FILTER -A INPUT -i lo -d 127.0.0.0/8 -s 127.0.0.0/8 -j ACCEPT
$FILTER -A INPUT -i "$LAN_IF" -d "$LAN_IPADDR" -s "$LAN_IPADDR/$LAN_NETMASK" -j ACCEPT
+ $FILTER -A INPUT -i "$LAN_IF" -d "$LAN_IPADDR" -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
$FILTER -P INPUT DROP
$FILTER -P FORWARD DROP
@@ -41,10 +42,10 @@ ipv4_up() {
#########################
ipv6_up() {
- $FILTER -A INPUT -i lo -j ACCEPT
+ $FILTER6 -A INPUT -i lo -j ACCEPT
- $FILTER -P INPUT DROP
- $FILTER -P FORWARD DROP
+ $FILTER6 -P INPUT DROP
+ $FILTER6 -P FORWARD DROP
echo -n "success"
}