Switch to nft interface by default
This commit is contained in:
@@ -1,9 +1,35 @@
|
||||
name: iptables
|
||||
description: userspace CLI program used to configure the Linux packet filtering ruleset
|
||||
version: 1.8.11
|
||||
revision: 2
|
||||
revision: 3
|
||||
url: https://www.netfilter.org/projects/iptables/index.html
|
||||
license: GPL2-only
|
||||
architecture: any
|
||||
depends: ["bash"]
|
||||
type: source
|
||||
keep:
|
||||
- etc/ethertypes
|
||||
- etc/iptables/iptables.rules
|
||||
- etc/iptables/ip6tables.rules
|
||||
depends:
|
||||
- libnetfilter_conntrack
|
||||
- libnfnetlink
|
||||
- libnftnl
|
||||
- libpcap
|
||||
- nftables
|
||||
downloads:
|
||||
- url: https://www.netfilter.org/projects/iptables/files/iptables-${BPM_PKG_VERSION}.tar.xz
|
||||
extract_to: ${BPM_SOURCE}
|
||||
extract_strip_components: 1
|
||||
checksum: d87303d55ef8c92bcad4dd3f978b26d272013642b029425775f5bad1009fe7b2
|
||||
split_packages:
|
||||
- name: iptables
|
||||
conflicts:
|
||||
- iptables-legacy
|
||||
- name: iptables-legacy
|
||||
depends:
|
||||
- libnetfilter_conntrack
|
||||
- libnfnetlink
|
||||
- libnftnl
|
||||
- libpcap
|
||||
conflicts:
|
||||
- iptables
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
name: iptables
|
||||
description: IPv6 Packet Filtering Framework
|
||||
type: simple
|
||||
start_cmd: /etc/esvm/scripts/ip6tables.sh
|
||||
stop_cmd: /etc/esvm/scripts/iptables-flush.sh -6
|
||||
exit_method: stop_command
|
||||
@@ -0,0 +1,5 @@
|
||||
#!/bin/sh
|
||||
|
||||
[ ! -e /etc/iptables/ip6tables.rules ] && exit 0
|
||||
ip6tables-restore -w 3 /etc/iptables/ip6tables.rules || exit 1
|
||||
exec ip6tables pause
|
||||
@@ -1,14 +1,21 @@
|
||||
# Flush iptables (Code from archlinux)
|
||||
iptables=ip$1tables
|
||||
if ! type -p "$iptables" &>/dev/null; then
|
||||
echo "error: invalid argument"
|
||||
exit 1
|
||||
#!/bin/sh
|
||||
# Usage: iptables-flush [-6]
|
||||
|
||||
iptables=/usr/sbin/iptables
|
||||
tables="filter mangle raw"
|
||||
|
||||
if [ "$1" = "-6" ]; then
|
||||
iptables=/usr/bin/ip6tables
|
||||
else
|
||||
# Only ipv4 has a nat table
|
||||
tables="$tables nat"
|
||||
fi
|
||||
|
||||
while read -r table; do
|
||||
tables+=("/usr/share/iptables/empty-$table.rules")
|
||||
done <"/proc/net/ip$1_tables_names"
|
||||
for table in ${tables}; do
|
||||
$iptables -t "$table" -F
|
||||
$iptables -t "$table" -X
|
||||
done
|
||||
|
||||
if (( ${#tables[*]} )); then
|
||||
cat "${tables[@]}" | "$iptables-restore"
|
||||
fi
|
||||
for chain in INPUT FORWARD OUTPUT; do
|
||||
$iptables -P "$chain" ACCEPT
|
||||
done
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: iptables
|
||||
description: IPv4 Packet Filtering Framework
|
||||
type: simple
|
||||
start_cmd: /usr/sbin/iptables-restore /etc/iptables/iptables.rules
|
||||
start_cmd: /etc/esvm/scripts/iptables.sh
|
||||
stop_cmd: /etc/esvm/scripts/iptables-flush.sh
|
||||
exit_method: stop_command
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
#!/bin/sh
|
||||
|
||||
[ ! -e /etc/iptables/iptables.rules ] && exit 0
|
||||
iptables-restore -w 3 /etc/iptables/iptables.rules || exit 1
|
||||
exec iptables pause
|
||||
@@ -3,7 +3,7 @@
|
||||
:FORWARD DROP [0:0]
|
||||
:OUTPUT ACCEPT [0:0]
|
||||
-A INPUT -p icmp -j ACCEPT
|
||||
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
|
||||
-A INPUT -i lo -j ACCEPT
|
||||
-A INPUT -p tcp -j REJECT --reject-with tcp-reset
|
||||
-A INPUT -p udp -j REJECT --reject-with icmp-port-unreachable
|
||||
|
||||
@@ -2,40 +2,47 @@
|
||||
# BPM Expects the source code to be extracted into the automatically created 'source' directory which can be accessed using $BPM_SOURCE
|
||||
# BPM Expects the output files to be present in the automatically created 'output' directory which can be accessed using $BPM_OUTPUT
|
||||
|
||||
DOWNLOAD="https://www.netfilter.org/projects/iptables/files/iptables-${BPM_PKG_VERSION}.tar.xz"
|
||||
FILENAME="${DOWNLOAD##*/}"
|
||||
|
||||
# The prepare function is executed in the root of the temp directory
|
||||
# This function is used for downloading files and putting them into the correct location
|
||||
prepare() {
|
||||
wget "$DOWNLOAD"
|
||||
tar -xvf "$FILENAME" --strip-components=1 -C "$BPM_SOURCE"
|
||||
}
|
||||
|
||||
# The build function is executed in the source directory
|
||||
# This function is used to compile the source code
|
||||
build() {
|
||||
./configure --prefix=/usr \
|
||||
--disable-nftables \
|
||||
--enable-libipq
|
||||
./configure --prefix=/usr --enable-bpf-compiler --enable-devel --enable-libipq --enable-shared
|
||||
make
|
||||
}
|
||||
|
||||
# The package function is executed in the source directory
|
||||
# This function is used to move the compiled files into the output directory
|
||||
package() {
|
||||
package_iptables() {
|
||||
make DESTDIR="$BPM_OUTPUT" install
|
||||
|
||||
# Link to xtables-nft-multi
|
||||
for x in {arp,eb,ip,ip6}tables{,-restore,-save}; do
|
||||
ln -sf xtables-nft-multi "$BPM_OUTPUT"/usr/sbin/"$x"
|
||||
done
|
||||
ln -sf /usr/sbin/xtables-nft-multi "$BPM_OUTPUT"/usr/bin/iptables-xml
|
||||
|
||||
# Install esvm service
|
||||
install -Dm755 "$BPM_WORKDIR"/ip{6,}tables.sh -t "$BPM_OUTPUT"/etc/esvm/scripts/
|
||||
install -Dm644 "$BPM_WORKDIR"/ip{6,}tables.esv -t "$BPM_OUTPUT"/etc/esvm/services/
|
||||
|
||||
# Install iptables rules
|
||||
install -Dm644 "$BPM_WORKDIR"/rules/{empty,simple_firewall}.rules -t "$BPM_OUTPUT"/etc/iptables/
|
||||
install -Dm644 "$BPM_WORKDIR"/rules/empty-* -t "$BPM_OUTPUT"/usr/share/iptables/
|
||||
|
||||
# Install package license
|
||||
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/COPYING
|
||||
}
|
||||
|
||||
package_iptables-legacy() {
|
||||
make DESTDIR="$BPM_OUTPUT" install
|
||||
|
||||
# Install esvm service
|
||||
install -Dm755 "$BPM_WORKDIR"/iptables-flush.sh "$BPM_OUTPUT"/etc/esvm/scripts/iptables-flush.sh
|
||||
install -Dm644 "$BPM_WORKDIR"/iptables.esv "$BPM_OUTPUT"/etc/esvm/services/iptables.esv
|
||||
install -Dm755 "$BPM_WORKDIR"/ip{6,}tables.sh -t "$BPM_OUTPUT"/etc/esvm/scripts/
|
||||
install -Dm644 "$BPM_WORKDIR"/ip{6,}tables.esv -t "$BPM_OUTPUT"/etc/esvm/services/
|
||||
|
||||
# Rules from Arch Linux
|
||||
install -Dm644 "$BPM_WORKDIR"/rules/empty.rules "$BPM_OUTPUT"/etc/iptables/iptables.rules
|
||||
install -Dm644 "$BPM_WORKDIR"/rules/empty.rules "$BPM_OUTPUT"/etc/iptables/ip6tables.rules
|
||||
install -Dm644 "$BPM_WORKDIR"/rules/*.rules -t "$BPM_OUTPUT"/usr/share/iptables/
|
||||
ln -srt "$BPM_OUTPUT"/etc/iptables "$BPM_OUTPUT"/usr/share/iptables/{empty,simple_firewall}.rules
|
||||
# Install iptables rules
|
||||
install -Dm644 "$BPM_WORKDIR"/rules/{empty,simple_firewall}.rules -t "$BPM_OUTPUT"/etc/iptables/
|
||||
install -Dm644 "$BPM_WORKDIR"/rules/empty-* -t "$BPM_OUTPUT"/usr/share/iptables/
|
||||
|
||||
# Install package license
|
||||
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/LICENSE
|
||||
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/COPYING
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user