fix ssh
This commit is contained in:
@@ -14,7 +14,7 @@ in{
|
|||||||
type filter hook input priority filter; policy drop;
|
type filter hook input priority filter; policy drop;
|
||||||
ct state established,related accept
|
ct state established,related accept
|
||||||
iifname "lo" accept
|
iifname "lo" accept
|
||||||
tcp dport {22} accept
|
tcp dport {422, 22} accept
|
||||||
${if builtins.length cfg.db > 0 then ''tcp dport {5432, 6379} ip saddr { 10.0.0.0/8, 169.254.0.0/16 } accept'' else ""}
|
${if builtins.length cfg.db > 0 then ''tcp dport {5432, 6379} ip saddr { 10.0.0.0/8, 169.254.0.0/16 } accept'' else ""}
|
||||||
${if cfg.web then ''tcp dport {80, 443} accept
|
${if cfg.web then ''tcp dport {80, 443} accept
|
||||||
udp dport {80, 443} accept'' else ""}
|
udp dport {80, 443} accept'' else ""}
|
||||||
|
|||||||
Reference in New Issue
Block a user