Change the default policy to: reject all incoming traffic from WAN interface, leave LAN interface alone
parent
33aa41f864
commit
1d2eeade80
|
@ -1,6 +1,4 @@
|
|||
rules() {
|
||||
for chain in INPUT OUTPUT FORWARD; do
|
||||
:
|
||||
# iptables -P ${chain} DROP
|
||||
done
|
||||
iptables -t filter $append INPUT -i ${IF_WAN} -j REJECT --reject-with icmp-port-unreachable
|
||||
iptables -t filter $append FORWARD -i ${IF_WAN} -j REJECT --reject-with icmp-port-unreachable
|
||||
}
|
||||
|
|
Loading…
Reference in New Issue