Switch to nft interface by default
This commit is contained in:
@@ -1,9 +1,35 @@
|
|||||||
name: iptables
|
name: iptables
|
||||||
description: userspace CLI program used to configure the Linux packet filtering ruleset
|
description: userspace CLI program used to configure the Linux packet filtering ruleset
|
||||||
version: 1.8.11
|
version: 1.8.11
|
||||||
revision: 2
|
revision: 3
|
||||||
url: https://www.netfilter.org/projects/iptables/index.html
|
url: https://www.netfilter.org/projects/iptables/index.html
|
||||||
license: GPL2-only
|
license: GPL2-only
|
||||||
architecture: any
|
architecture: any
|
||||||
depends: ["bash"]
|
|
||||||
type: source
|
type: source
|
||||||
|
keep:
|
||||||
|
- etc/ethertypes
|
||||||
|
- etc/iptables/iptables.rules
|
||||||
|
- etc/iptables/ip6tables.rules
|
||||||
|
depends:
|
||||||
|
- libnetfilter_conntrack
|
||||||
|
- libnfnetlink
|
||||||
|
- libnftnl
|
||||||
|
- libpcap
|
||||||
|
- nftables
|
||||||
|
downloads:
|
||||||
|
- url: https://www.netfilter.org/projects/iptables/files/iptables-${BPM_PKG_VERSION}.tar.xz
|
||||||
|
extract_to: ${BPM_SOURCE}
|
||||||
|
extract_strip_components: 1
|
||||||
|
checksum: d87303d55ef8c92bcad4dd3f978b26d272013642b029425775f5bad1009fe7b2
|
||||||
|
split_packages:
|
||||||
|
- name: iptables
|
||||||
|
conflicts:
|
||||||
|
- iptables-legacy
|
||||||
|
- name: iptables-legacy
|
||||||
|
depends:
|
||||||
|
- libnetfilter_conntrack
|
||||||
|
- libnfnetlink
|
||||||
|
- libnftnl
|
||||||
|
- libpcap
|
||||||
|
conflicts:
|
||||||
|
- iptables
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
name: iptables
|
||||||
|
description: IPv6 Packet Filtering Framework
|
||||||
|
type: simple
|
||||||
|
start_cmd: /etc/esvm/scripts/ip6tables.sh
|
||||||
|
stop_cmd: /etc/esvm/scripts/iptables-flush.sh -6
|
||||||
|
exit_method: stop_command
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
|
||||||
|
[ ! -e /etc/iptables/ip6tables.rules ] && exit 0
|
||||||
|
ip6tables-restore -w 3 /etc/iptables/ip6tables.rules || exit 1
|
||||||
|
exec ip6tables pause
|
||||||
@@ -1,14 +1,21 @@
|
|||||||
# Flush iptables (Code from archlinux)
|
#!/bin/sh
|
||||||
iptables=ip$1tables
|
# Usage: iptables-flush [-6]
|
||||||
if ! type -p "$iptables" &>/dev/null; then
|
|
||||||
echo "error: invalid argument"
|
iptables=/usr/sbin/iptables
|
||||||
exit 1
|
tables="filter mangle raw"
|
||||||
|
|
||||||
|
if [ "$1" = "-6" ]; then
|
||||||
|
iptables=/usr/bin/ip6tables
|
||||||
|
else
|
||||||
|
# Only ipv4 has a nat table
|
||||||
|
tables="$tables nat"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
while read -r table; do
|
for table in ${tables}; do
|
||||||
tables+=("/usr/share/iptables/empty-$table.rules")
|
$iptables -t "$table" -F
|
||||||
done <"/proc/net/ip$1_tables_names"
|
$iptables -t "$table" -X
|
||||||
|
done
|
||||||
|
|
||||||
if (( ${#tables[*]} )); then
|
for chain in INPUT FORWARD OUTPUT; do
|
||||||
cat "${tables[@]}" | "$iptables-restore"
|
$iptables -P "$chain" ACCEPT
|
||||||
fi
|
done
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
name: iptables
|
name: iptables
|
||||||
description: IPv4 Packet Filtering Framework
|
description: IPv4 Packet Filtering Framework
|
||||||
type: simple
|
type: simple
|
||||||
start_cmd: /usr/sbin/iptables-restore /etc/iptables/iptables.rules
|
start_cmd: /etc/esvm/scripts/iptables.sh
|
||||||
stop_cmd: /etc/esvm/scripts/iptables-flush.sh
|
stop_cmd: /etc/esvm/scripts/iptables-flush.sh
|
||||||
exit_method: stop_command
|
exit_method: stop_command
|
||||||
|
|||||||
@@ -0,0 +1,5 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
|
||||||
|
[ ! -e /etc/iptables/iptables.rules ] && exit 0
|
||||||
|
iptables-restore -w 3 /etc/iptables/iptables.rules || exit 1
|
||||||
|
exec iptables pause
|
||||||
@@ -3,7 +3,7 @@
|
|||||||
:FORWARD DROP [0:0]
|
:FORWARD DROP [0:0]
|
||||||
:OUTPUT ACCEPT [0:0]
|
:OUTPUT ACCEPT [0:0]
|
||||||
-A INPUT -p icmp -j ACCEPT
|
-A INPUT -p icmp -j ACCEPT
|
||||||
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
|
||||||
-A INPUT -i lo -j ACCEPT
|
-A INPUT -i lo -j ACCEPT
|
||||||
-A INPUT -p tcp -j REJECT --reject-with tcp-reset
|
-A INPUT -p tcp -j REJECT --reject-with tcp-reset
|
||||||
-A INPUT -p udp -j REJECT --reject-with icmp-port-unreachable
|
-A INPUT -p udp -j REJECT --reject-with icmp-port-unreachable
|
||||||
|
|||||||
@@ -2,40 +2,47 @@
|
|||||||
# BPM Expects the source code to be extracted into the automatically created 'source' directory which can be accessed using $BPM_SOURCE
|
# BPM Expects the source code to be extracted into the automatically created 'source' directory which can be accessed using $BPM_SOURCE
|
||||||
# BPM Expects the output files to be present in the automatically created 'output' directory which can be accessed using $BPM_OUTPUT
|
# BPM Expects the output files to be present in the automatically created 'output' directory which can be accessed using $BPM_OUTPUT
|
||||||
|
|
||||||
DOWNLOAD="https://www.netfilter.org/projects/iptables/files/iptables-${BPM_PKG_VERSION}.tar.xz"
|
|
||||||
FILENAME="${DOWNLOAD##*/}"
|
|
||||||
|
|
||||||
# The prepare function is executed in the root of the temp directory
|
|
||||||
# This function is used for downloading files and putting them into the correct location
|
|
||||||
prepare() {
|
|
||||||
wget "$DOWNLOAD"
|
|
||||||
tar -xvf "$FILENAME" --strip-components=1 -C "$BPM_SOURCE"
|
|
||||||
}
|
|
||||||
|
|
||||||
# The build function is executed in the source directory
|
# The build function is executed in the source directory
|
||||||
# This function is used to compile the source code
|
# This function is used to compile the source code
|
||||||
build() {
|
build() {
|
||||||
./configure --prefix=/usr \
|
./configure --prefix=/usr --enable-bpf-compiler --enable-devel --enable-libipq --enable-shared
|
||||||
--disable-nftables \
|
|
||||||
--enable-libipq
|
|
||||||
make
|
make
|
||||||
}
|
}
|
||||||
|
|
||||||
# The package function is executed in the source directory
|
# The package function is executed in the source directory
|
||||||
# This function is used to move the compiled files into the output directory
|
# This function is used to move the compiled files into the output directory
|
||||||
package() {
|
package_iptables() {
|
||||||
|
make DESTDIR="$BPM_OUTPUT" install
|
||||||
|
|
||||||
|
# Link to xtables-nft-multi
|
||||||
|
for x in {arp,eb,ip,ip6}tables{,-restore,-save}; do
|
||||||
|
ln -sf xtables-nft-multi "$BPM_OUTPUT"/usr/sbin/"$x"
|
||||||
|
done
|
||||||
|
ln -sf /usr/sbin/xtables-nft-multi "$BPM_OUTPUT"/usr/bin/iptables-xml
|
||||||
|
|
||||||
|
# Install esvm service
|
||||||
|
install -Dm755 "$BPM_WORKDIR"/ip{6,}tables.sh -t "$BPM_OUTPUT"/etc/esvm/scripts/
|
||||||
|
install -Dm644 "$BPM_WORKDIR"/ip{6,}tables.esv -t "$BPM_OUTPUT"/etc/esvm/services/
|
||||||
|
|
||||||
|
# Install iptables rules
|
||||||
|
install -Dm644 "$BPM_WORKDIR"/rules/{empty,simple_firewall}.rules -t "$BPM_OUTPUT"/etc/iptables/
|
||||||
|
install -Dm644 "$BPM_WORKDIR"/rules/empty-* -t "$BPM_OUTPUT"/usr/share/iptables/
|
||||||
|
|
||||||
|
# Install package license
|
||||||
|
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/COPYING
|
||||||
|
}
|
||||||
|
|
||||||
|
package_iptables-legacy() {
|
||||||
make DESTDIR="$BPM_OUTPUT" install
|
make DESTDIR="$BPM_OUTPUT" install
|
||||||
|
|
||||||
# Install esvm service
|
# Install esvm service
|
||||||
install -Dm755 "$BPM_WORKDIR"/iptables-flush.sh "$BPM_OUTPUT"/etc/esvm/scripts/iptables-flush.sh
|
install -Dm755 "$BPM_WORKDIR"/ip{6,}tables.sh -t "$BPM_OUTPUT"/etc/esvm/scripts/
|
||||||
install -Dm644 "$BPM_WORKDIR"/iptables.esv "$BPM_OUTPUT"/etc/esvm/services/iptables.esv
|
install -Dm644 "$BPM_WORKDIR"/ip{6,}tables.esv -t "$BPM_OUTPUT"/etc/esvm/services/
|
||||||
|
|
||||||
# Rules from Arch Linux
|
# Install iptables rules
|
||||||
install -Dm644 "$BPM_WORKDIR"/rules/empty.rules "$BPM_OUTPUT"/etc/iptables/iptables.rules
|
install -Dm644 "$BPM_WORKDIR"/rules/{empty,simple_firewall}.rules -t "$BPM_OUTPUT"/etc/iptables/
|
||||||
install -Dm644 "$BPM_WORKDIR"/rules/empty.rules "$BPM_OUTPUT"/etc/iptables/ip6tables.rules
|
install -Dm644 "$BPM_WORKDIR"/rules/empty-* -t "$BPM_OUTPUT"/usr/share/iptables/
|
||||||
install -Dm644 "$BPM_WORKDIR"/rules/*.rules -t "$BPM_OUTPUT"/usr/share/iptables/
|
|
||||||
ln -srt "$BPM_OUTPUT"/etc/iptables "$BPM_OUTPUT"/usr/share/iptables/{empty,simple_firewall}.rules
|
|
||||||
|
|
||||||
# Install package license
|
# Install package license
|
||||||
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/LICENSE
|
install -Dm644 "$BPM_SOURCE"/COPYING "$BPM_OUTPUT"/usr/share/licenses/iptables/COPYING
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user