|
@@ -118,97 +118,6 @@ function configure_firewall_ping {
|
118
|
118
|
mark_completed $FUNCNAME
|
119
|
119
|
}
|
120
|
120
|
|
121
|
|
-function configure_firewall_for_avahi {
|
122
|
|
- if [[ $(is_completed $FUNCNAME) == "1" ]]; then
|
123
|
|
- return
|
124
|
|
- fi
|
125
|
|
- iptables -A INPUT -p tcp --dport 548 -j ACCEPT
|
126
|
|
- iptables -A INPUT -p udp --dport 548 -j ACCEPT
|
127
|
|
- iptables -A INPUT -p tcp --dport 5353 -j ACCEPT
|
128
|
|
- iptables -A INPUT -p udp --dport 5353 -j ACCEPT
|
129
|
|
- iptables -A INPUT -p tcp --dport 5354 -j ACCEPT
|
130
|
|
- iptables -A INPUT -p udp --dport 5354 -j ACCEPT
|
131
|
|
- function_check save_firewall_settings
|
132
|
|
- save_firewall_settings
|
133
|
|
- mark_completed $FUNCNAME
|
134
|
|
-}
|
135
|
|
-
|
136
|
|
-function configure_firewall_for_dns {
|
137
|
|
- if [[ $(is_completed $FUNCNAME) == "1" ]]; then
|
138
|
|
- return
|
139
|
|
- fi
|
140
|
|
- if [[ $INSTALLED_WITHIN_DOCKER == "yes" ]]; then
|
141
|
|
- # docker does its own firewalling
|
142
|
|
- return
|
143
|
|
- fi
|
144
|
|
- iptables -A INPUT -p udp -m udp --dport 1024:65535 --sport 53 -j ACCEPT
|
145
|
|
- function_check save_firewall_settings
|
146
|
|
- save_firewall_settings
|
147
|
|
- mark_completed $FUNCNAME
|
148
|
|
-}
|
149
|
|
-
|
150
|
|
-function configure_firewall_for_web_access {
|
151
|
|
- if [[ $(is_completed $FUNCNAME) == "1" ]]; then
|
152
|
|
- return
|
153
|
|
- fi
|
154
|
|
- if [[ $INSTALLED_WITHIN_DOCKER == "yes" ]]; then
|
155
|
|
- # docker does its own firewalling
|
156
|
|
- return
|
157
|
|
- fi
|
158
|
|
- if [[ $ONION_ONLY != "no" ]]; then
|
159
|
|
- return
|
160
|
|
- fi
|
161
|
|
- firewall_remove 80 tcp
|
162
|
|
- firewall_remove 443 tcp
|
163
|
|
- mark_completed $FUNCNAME
|
164
|
|
-}
|
165
|
|
-
|
166
|
|
-function configure_firewall_for_web_server {
|
167
|
|
- if [[ $(is_completed $FUNCNAME) == "1" ]]; then
|
168
|
|
- return
|
169
|
|
- fi
|
170
|
|
- if [[ $INSTALLED_WITHIN_DOCKER == "yes" ]]; then
|
171
|
|
- # docker does its own firewalling
|
172
|
|
- return
|
173
|
|
- fi
|
174
|
|
- if [[ $ONION_ONLY != "no" ]]; then
|
175
|
|
- return
|
176
|
|
- fi
|
177
|
|
-
|
178
|
|
- firewall_add HTTP 80 tcp
|
179
|
|
- firewall_add HTTPS 443 tcp
|
180
|
|
- mark_completed $FUNCNAME
|
181
|
|
-}
|
182
|
|
-
|
183
|
|
-function configure_firewall_for_ssh {
|
184
|
|
- if [[ $(is_completed $FUNCNAME) == "1" ]]; then
|
185
|
|
- return
|
186
|
|
- fi
|
187
|
|
- if [[ $INSTALLED_WITHIN_DOCKER == "yes" ]]; then
|
188
|
|
- # docker does its own firewalling
|
189
|
|
- return
|
190
|
|
- fi
|
191
|
|
-
|
192
|
|
- firewall_add SSH ${SSH_PORT} tcp
|
193
|
|
- mark_completed $FUNCNAME
|
194
|
|
-}
|
195
|
|
-
|
196
|
|
-function configure_firewall_for_git {
|
197
|
|
- if [[ $(is_completed $FUNCNAME) == "1" ]]; then
|
198
|
|
- return
|
199
|
|
- fi
|
200
|
|
- if [[ $INSTALLED_WITHIN_DOCKER == "yes" ]]; then
|
201
|
|
- # docker does its own firewalling
|
202
|
|
- return
|
203
|
|
- fi
|
204
|
|
- if [[ $ONION_ONLY != "no" ]]; then
|
205
|
|
- return
|
206
|
|
- fi
|
207
|
|
-
|
208
|
|
- firewall_add Git 9418 tcp
|
209
|
|
- mark_completed $FUNCNAME
|
210
|
|
-}
|
211
|
|
-
|
212
|
121
|
function configure_internet_protocol {
|
213
|
122
|
if [[ $(is_completed $FUNCNAME) == "1" ]]; then
|
214
|
123
|
return
|