From 7a6121308829964f27346c558df420a29383b301 Mon Sep 17 00:00:00 2001 From: OldTyT Date: Fri, 23 Feb 2024 17:17:18 +0000 Subject: [PATCH] chore: added create table DOCKER-USER --- templates/custom.firewall-restore.j2 | 2 ++ 1 file changed, 2 insertions(+) diff --git a/templates/custom.firewall-restore.j2 b/templates/custom.firewall-restore.j2 index 27d8822..d32eb3e 100644 --- a/templates/custom.firewall-restore.j2 +++ b/templates/custom.firewall-restore.j2 @@ -12,6 +12,7 @@ iptables -I INPUT 1 -p tcp -m multiport --dports {{ whitelist_ssh_port }} -j f2b iptables -N enemy_input iptables -I INPUT 1 -i {{ whitelist_interface }} -j enemy_input +iptables -N DOCKER-USER iptables -I DOCKER-USER 1 -i {{ whitelist_interface }} -j enemy_input iptables -I enemy_input 1 -p tcp -m multiport ! --dports {{ whitelist_public_port|join(',') }} -m set --match-set {{ whitelist_ip4_name }} src -j ACCEPT iptables -I enemy_input 2 -m set --match-set {{ whitelist_ip4_name }} src -j ACCEPT @@ -26,6 +27,7 @@ ip6tables -I INPUT 1 -p tcp -m multiport --dports {{ whitelist_ssh_port }} -j f2 ip6tables -N enemy_input ip6tables -I INPUT 1 -i {{ whitelist_interface }} -j enemy_input +ip6tables -N DOCKER-USER ip6tables -I DOCKER-USER 1 -i {{ whitelist_interface }} -j enemy_input ip6tables -I enemy_input 1 -p tcp -m multiport ! --dports {{ whitelist_public_port|join(',') }} -m set --match-set {{ whitelist_ip6_name }} src -j ACCEPT ip6tables -I enemy_input 2 -m set --match-set {{ whitelist_ip6_name }} src -j ACCEPT