From 5a9655164f18aae5498b00f99a79e268c9e87f45 Mon Sep 17 00:00:00 2001 From: OldTyT Date: Mon, 26 Feb 2024 08:56:23 +0000 Subject: [PATCH] fix: ipv6 rules generate --- templates/custom.firewall-restore.j2 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/templates/custom.firewall-restore.j2 b/templates/custom.firewall-restore.j2 index 6cc5a03..c07b055 100644 --- a/templates/custom.firewall-restore.j2 +++ b/templates/custom.firewall-restore.j2 @@ -32,7 +32,7 @@ ip6tables -I INPUT 1 -i {{ whitelist_interface }} -j enemy_input ip6tables -N DOCKER-USER ip6tables -I DOCKER-USER 1 -i {{ whitelist_interface }} -j enemy_input ip6tables -I enemy_input 1 -p tcp -m multiport ! --dports {{ whitelist_public_tcp_port|join(',') }} -m set --match-set {{ whitelist_ip6_name }} src -j ACCEPT -ip6tables -I enemy_input 2 -p udp -m multiport ! --dports {{ whitelist_public_udp_port|join(',') }} -m set --match-set {{ whitelist_ip4_name }} src -j ACCEPT +ip6tables -I enemy_input 2 -p udp -m multiport ! --dports {{ whitelist_public_udp_port|join(',') }} -m set --match-set {{ whitelist_ip6_name }} src -j ACCEPT ip6tables -I enemy_input 3 -m set --match-set {{ whitelist_ip6_name }} src -j ACCEPT ip6tables -I enemy_input 4 -m state --state RELATED,ESTABLISHED -j ACCEPT ip6tables -I enemy_input 5 -p tcp -m multiport ! --dports {{ whitelist_public_tcp_port|join(',') }} -j DROP