From 2083df18d17e354292c4bfc6b20555a3bea583fa Mon Sep 17 00:00:00 2001 From: Bjoern Franke Date: Fri, 23 Nov 2012 17:41:58 +0100 Subject: [PATCH] ssh reopened in firewall config for debugging purposes, should be closed again in stable release --- bsp/default/root_file_system/etc/firewall.user | 2 ++ 1 file changed, 2 insertions(+) diff --git a/bsp/default/root_file_system/etc/firewall.user b/bsp/default/root_file_system/etc/firewall.user index d6a19311..fcd3e048 100755 --- a/bsp/default/root_file_system/etc/firewall.user +++ b/bsp/default/root_file_system/etc/firewall.user @@ -7,5 +7,7 @@ iptables -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss- # Das wirkt bei kleinen Geräten wir ein DOS WAN=$(uci get network.wan.ifname) iptables -A INPUT -i $WAN -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT +#ssh open for debugging purposes, should be removed in stable release +iptables -A INPUT -i $WAN -p tcp --dport 22 -j ACCEPT iptables -A INPUT -i $WAN -j REJECT