From ead0cc8f6a8ef5673d5a645d5d43f02d9cea775d Mon Sep 17 00:00:00 2001 From: hiddify Date: Tue, 7 Feb 2023 21:19:16 +0100 Subject: [PATCH] allow ports by default --- common/run.sh | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/common/run.sh b/common/run.sh index f38fe6258..f6d4b5e6d 100644 --- a/common/run.sh +++ b/common/run.sh @@ -2,13 +2,15 @@ function add2iptables(){ iptables -C $1 || echo "adding rule $1" && iptables -I $1 } + +add2iptables "INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT" +add2iptables "INPUT -i lo -j ACCEPT" +add2iptables "INPUT -p tcp --dport 443 -j ACCEPT" +add2iptables "INPUT -p udp --dport 53 -j ACCEPT" +add2iptables "INPUT -p tcp --dport 80 -j ACCEPT" +add2iptables "INPUT -p tcp --dport 22 -j ACCEPT" + if [[ $ENABLE_FIREWALL == true ]]; then - add2iptables "INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT" - add2iptables "INPUT -i lo -j ACCEPT" - add2iptables "INPUT -p tcp --dport 443 -j ACCEPT" - add2iptables "INPUT -p udp --dport 53 -j ACCEPT" - add2iptables "INPUT -p tcp --dport 80 -j ACCEPT" - add2iptables "INPUT -p tcp --dport 22 -j ACCEPT" iptables -P INPUT DROP iptables-save > /etc/iptables/rules.v4 else