From 0a969afabc466593adc9fd3ca9f8923fc254e97b Mon Sep 17 00:00:00 2001 From: Gerard Ryan Date: Sat, 20 Feb 2021 17:59:58 +1000 Subject: [PATCH] dockerd: set docker zone chain defaults to ACCEPT * Since the docker0 is a private network by default we can be more accepting like the LAN is by default Signed-off-by: Gerard Ryan --- utils/dockerd/files/dockerd.init | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/utils/dockerd/files/dockerd.init b/utils/dockerd/files/dockerd.init index 54268f1258..2eb272a70c 100755 --- a/utils/dockerd/files/dockerd.init +++ b/utils/dockerd/files/dockerd.init @@ -66,9 +66,9 @@ uciadd() { uci_quiet add firewall zone uci_quiet rename firewall.@zone[-1]="${zone}" uci_quiet set firewall.@zone[-1].network="${iface}" - uci_quiet set firewall.@zone[-1].input="REJECT" + uci_quiet set firewall.@zone[-1].input="ACCEPT" uci_quiet set firewall.@zone[-1].output="ACCEPT" - uci_quiet set firewall.@zone[-1].forward="REJECT" + uci_quiet set firewall.@zone[-1].forward="ACCEPT" uci_quiet set firewall.@zone[-1].name="${zone}" uci_quiet commit firewall fi