#!/bin/sh # network : ipv6:ipv6:::ipv6/mask || dns6/mask # Local is all ips registered local network="$( ip6toolsGetIps | $cmdTr -s ' ' ';' )" # clients : PROTO ; PORT ; UID/GID ; UID/GID ; UID/GID .... | # servers : PROTO ; PORT ; UID/GID ; UID/GID ; UID/GID .... | # forward : PROTO ; PORT | # -- CLIENT -- # [ UDP/TCP/DOMAIN ] #local clients="$clients|UDP ;domain ;root/root;1000/1000;_apt/nogroup" #local clients="$clients|TCP ;domain ;root/root;1000/1000;Debian-exim/Debian-exim;systemd-timesync/systemd-timesync;_apt/nogroup" # -- SERVER -- #local servers="$servers|UDP ;domain ;1000/1000" #local servers="$servers|TCP ;domain ;1000/1000" # ruleOut : iptables -t filter -A OUTPUT -o ""$eth"" -j ""$rulesOut"" # ruleIn : iptables -t filter -A INPUT -i ""$eth"" -j ""$rulesIn"" # dropOut : iptables -t filter -A OUTPUT -o ""$eth"" -j ""$rulesOut"" # dropIn : iptables -t filter -A INPUT -i ""$eth"" -j ""$rulesIn"" local ruleEthIn="$ruleEthIn ;dnsRNDC_in | -s "$ip" -d "$ip" -p udp" local ruleEthOut="$ruleEthOut;dnsRNDC_out | -d "$ip" -s "$ip" -p udp"