Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # By default drop everything. RELATED and ESTABLISHED are allowed
- # to keep network operational and not disturb any connections that
- # have been established outbound. Similarly, to avoid connman DNS
- # resolving from breaking a rule for allowing all incoming on loopback
- # is added.
- [General]
- # IPv4 rules and policies.
- IPv4.INPUT.RULES = -p udp -m multiport --ports 67:68 -j ACCEPT;-m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT; -i lo -j ACCEPT
- IPv4.INPUT.POLICY = DROP
- # IPv6 rules and policies.
- IPv6.INPUT.RULES = -p udp -m multiport --ports 546:547 -j ACCEPT; -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT; -i lo -j ACCEPT
- IPv6.INPUT.POLICY = DROP
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement