mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-09 10:42:54 +01:00
update fw rules
This commit is contained in:
@@ -101,10 +101,6 @@ COMMIT
|
|||||||
-A FORWARD -o sobridge -j DOCKER
|
-A FORWARD -o sobridge -j DOCKER
|
||||||
-A FORWARD -i sobridge ! -o sobridge -j ACCEPT
|
-A FORWARD -i sobridge ! -o sobridge -j ACCEPT
|
||||||
-A FORWARD -i sobridge -o sobridge -j ACCEPT
|
-A FORWARD -i sobridge -o sobridge -j ACCEPT
|
||||||
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
|
||||||
-A FORWARD -i lo -j ACCEPT
|
|
||||||
-A FORWARD -m conntrack --ctstate INVALID -j DROP
|
|
||||||
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
|
|
||||||
-A OUTPUT -p icmp -m icmp --icmp-type 14 -j DROP
|
-A OUTPUT -p icmp -m icmp --icmp-type 14 -j DROP
|
||||||
|
|
||||||
{%- for rule in D2 %}
|
{%- for rule in D2 %}
|
||||||
|
|||||||
Reference in New Issue
Block a user