Skip to content
Snippets Groups Projects
Commit 71add551 authored by Bob Mottram's avatar Bob Mottram
Browse files

More obvious variable name

parent aec19a48
No related branches found
No related tags found
No related merge requests found
......@@ -33,6 +33,7 @@
FIREWALL_CONFIG=$HOME/${PROJECT_NAME}-firewall.cfg
FIREWALL_DOMAINS=$HOME/${PROJECT_NAME}-firewall-domains.cfg
FIREWALL_EIFACE=eth0
EXTERNAL_IPV4_ADDRESS=
function save_firewall_settings {
iptables-save > /etc/firewall.conf
......@@ -110,8 +111,8 @@ function enable_ipv6 {
}
function firewall_deny_forwarding {
read_config_param CURRENT_IPV4_ADDRESS
if [ ! $CURRENT_IPV4_ADDRESS ]; then
read_config_param EXTERNAL_IPV4_ADDRESS
if [ ! $EXTERNAL_IPV4_ADDRESS ]; then
return
fi
iptables -D INPUT -i ${FIREWALL_EIFACE} -m state --state NEW -p udp --dport 1194 -j ACCEPT
......@@ -119,13 +120,13 @@ function firewall_deny_forwarding {
iptables -D FORWARD -i tun+ -j ACCEPT
iptables -D FORWARD -i tun+ -o ${FIREWALL_EIFACE} -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -D FORWARD -i ${FIREWALL_EIFACE} -o tun+ -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -t nat -D POSTROUTING -s ${CURRENT_IPV4_ADDRESS}/24 -o ${FIREWALL_EIFACE} -j MASQUERADE
iptables -t nat -D POSTROUTING -s ${EXTERNAL_IPV4_ADDRESS}/24 -o ${FIREWALL_EIFACE} -j MASQUERADE
iptables -D OUTPUT -o tun+ -j ACCEPT
save_firewall_settings
}
function firewall_allow_forwarding {
curr_ipv4_address=$(get_ipv4_address)
curr_ipv4_address=$(get_external_ipv4_address)
iptables -A INPUT -i ${FIREWALL_EIFACE} -m state --state NEW -p udp --dport 1194 -j ACCEPT
iptables -A INPUT -i tun+ -j ACCEPT
iptables -A FORWARD -i tun+ -j ACCEPT
......@@ -133,7 +134,7 @@ function firewall_allow_forwarding {
iptables -A FORWARD -i ${FIREWALL_EIFACE} -o tun+ -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -t nat -A POSTROUTING -s ${curr_ipv4_address}/24 -o ${FIREWALL_EIFACE} -j MASQUERADE
iptables -A OUTPUT -o tun+ -j ACCEPT
write_config_param CURRENT_IPV4_ADDRESS "$curr_ipv4_address"
write_config_param EXTERNAL_IPV4_ADDRESS "$curr_external_ipv4_address"
save_firewall_settings
}
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment