From 0733bccbddd3cc6d026a641cc1f0e5cdc4d084c2 Mon Sep 17 00:00:00 2001 From: Daniel Ehlers Date: Tue, 6 May 2014 21:24:04 +0200 Subject: [PATCH] gluon-mesh-batman-adv: Do not ACCEPT incoming packets. For security reasons we should not accept incoming packets per default and instead allow specific services on specific interfaces. --- .../lib/gluon/upgrade/mesh-batman-adv/invariant/011-mesh | 7 ------- 1 file changed, 7 deletions(-) diff --git a/gluon/gluon-mesh-batman-adv/files/lib/gluon/upgrade/mesh-batman-adv/invariant/011-mesh b/gluon/gluon-mesh-batman-adv/files/lib/gluon/upgrade/mesh-batman-adv/invariant/011-mesh index d48bb68..6bbf63f 100755 --- a/gluon/gluon-mesh-batman-adv/files/lib/gluon/upgrade/mesh-batman-adv/invariant/011-mesh +++ b/gluon/gluon-mesh-batman-adv/files/lib/gluon/upgrade/mesh-batman-adv/invariant/011-mesh @@ -29,13 +29,6 @@ uci_set firewall client input 'ACCEPT' uci_set firewall client output 'ACCEPT' uci_set firewall client forward 'REJECT' -config_load firewall -accept_input_on_wan() { - config_get name "$1" name - [ "$name" = 'wan' ] && uci_set firewall "$1" input 'ACCEPT' -} -config_foreach accept_input_on_wan 'zone' - uci_commit firewall uci_set dhcp '@dnsmasq[0]' boguspriv '0'