From 483ae6fc9aa8768772ab42567dc6b9636267695d Mon Sep 17 00:00:00 2001 From: Astro Date: Sat, 14 Apr 2018 21:50:38 +0200 Subject: [PATCH] firewall/priv-stateful: fix rules --- salt/firewall/priv-stateful.sh | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/salt/firewall/priv-stateful.sh b/salt/firewall/priv-stateful.sh index 0ed2d6c..4167cb4 100644 --- a/salt/firewall/priv-stateful.sh +++ b/salt/firewall/priv-stateful.sh @@ -12,8 +12,9 @@ if echo "$IFACE" | grep priv >/dev/null; then # loopback iptables -A FORWARD -i lo -j ACCEPT ip6tables -A FORWARD -i lo -j ACCEPT - # DHCP - iptables -A FORWARD -i $IFACE -p udp --dport 67 -j ACCEPT + # Trust priv + iptables -A FORWARD -i $IFACE -j ACCEPT + ip6tables -A FORWARD -i $IFACE -j ACCEPT # Deny by default iptables -A FORWARD -j REJECT ip6tables -A FORWARD -j REJECT