瀏覽代碼

More firewall settings

Bob Mottram 11 年之前
父節點
當前提交
417bf366ab
共有 1 個文件被更改,包括 5 次插入0 次删除
  1. 5
    0
      beaglebone.txt

+ 5
- 0
beaglebone.txt 查看文件

507
 iptables -X
507
 iptables -X
508
 
508
 
509
 # Drop any IPv6 traffic
509
 # Drop any IPv6 traffic
510
+ip6tables -A INPUT -p icmp -j DROP
510
 ip6tables -A INPUT -p tcp -j DROP
511
 ip6tables -A INPUT -p tcp -j DROP
511
 ip6tables -A INPUT -p udp -j DROP
512
 ip6tables -A INPUT -p udp -j DROP
512
 
513
 
615
 
616
 
616
 # Save the settings
617
 # Save the settings
617
 iptables-save > /etc/firewall.conf
618
 iptables-save > /etc/firewall.conf
619
+ip6tables-save > /etc/firewall6.conf
618
 echo '#!/bin/sh' > /etc/network/if-up.d/iptables
620
 echo '#!/bin/sh' > /etc/network/if-up.d/iptables
619
 echo 'iptables-restore < /etc/firewall.conf' >> /etc/network/if-up.d/iptables
621
 echo 'iptables-restore < /etc/firewall.conf' >> /etc/network/if-up.d/iptables
622
+echo 'ip6tables-restore < /etc/firewall6.conf' >> /etc/network/if-up.d/iptables
620
 chmod +x /etc/network/if-up.d/iptables
623
 chmod +x /etc/network/if-up.d/iptables
621
 #+END_SRC
624
 #+END_SRC
622
 
625
 
646
 net.ipv6.conf.all.accept_source_route = 0
649
 net.ipv6.conf.all.accept_source_route = 0
647
 net.ipv4.conf.default.rp_filter=1
650
 net.ipv4.conf.default.rp_filter=1
648
 net.ipv4.conf.all.rp_filter=1
651
 net.ipv4.conf.all.rp_filter=1
652
+net.ipv4.ip_forward=0
653
+net.ipv6.conf.all.forwarding=0
649
 #+END_SRC
654
 #+END_SRC
650
 
655
 
651
 And append the following:
656
 And append the following: