mirror of
https://github.com/coolsnowwolf/lede.git
synced 2025-04-16 04:13:31 +00:00
luci-app-ipsec-vpnd: rules security optimization
This commit is contained in:
parent
5d2b458012
commit
facd06ed14
@ -9,7 +9,7 @@ LUCI_TITLE:=LuCI support for IPSec VPN Server (IKEv1 with PSK and Xauth)
|
||||
LUCI_DEPENDS:=+strongswan +strongswan-minimal +strongswan-mod-xauth-generic +strongswan-mod-kernel-libipsec
|
||||
LUCI_PKGARCH:=all
|
||||
PKG_VERSION:=1.0
|
||||
PKG_RELEASE:=10
|
||||
PKG_RELEASE:=11
|
||||
|
||||
include $(TOPDIR)/feeds/luci/luci.mk
|
||||
|
||||
|
@ -18,9 +18,7 @@ uci -q batch <<-EOF >/dev/null
|
||||
set network.VPN.netmask="255.255.255.0"
|
||||
|
||||
commit network
|
||||
|
||||
set firewall.@defaults[0].forward="ACCEPT"
|
||||
|
||||
|
||||
delete firewall.ike
|
||||
add firewall rule
|
||||
rename firewall.@rule[-1]="ike"
|
||||
@ -62,6 +60,12 @@ uci -q batch <<-EOF >/dev/null
|
||||
set firewall.VPN.forward="ACCEPT"
|
||||
set firewall.VPN.output="ACCEPT"
|
||||
set firewall.VPN.network="VPN"
|
||||
|
||||
delete firewall.vpn
|
||||
set firewall.vpn=forwarding
|
||||
set firewall.vpn.name="vpn"
|
||||
set firewall.vpn.dest="wan"
|
||||
set firewall.vpn.src="VPN"
|
||||
|
||||
commit firewall
|
||||
EOF
|
||||
|
Loading…
Reference in New Issue
Block a user