diff --git a/ip6t-firewall-server b/ip6t-firewall-server index 936545e..b54ee84 100755 --- a/ip6t-firewall-server +++ b/ip6t-firewall-server @@ -1038,6 +1038,23 @@ else fi +# --- +# - local Resolver" +# --- + +echononl "\t\tlocal Resolver" +if [[ -n "$local_resolver_service" ]] && $local_resolver_service ; then + if [[ -z "$resolver_allowed_net" ]] ; then + echo_failed + else + $ip6t -A INPUT -p udp -s $resolver_allowed_net --dport $resolver_port -m conntrack --ctstate NEW -j ACCEPT + echo_done + fi +else + echo_skipped +fi + + # --- # - SSH out only # --- @@ -1690,7 +1707,7 @@ echo_done # --- echononl "\t\tNTP local Service" -if [[ -n $local_ntp_service ]] && $local_ntp_service ; then +if [[ -n "$local_ntp_service" ]] && $local_ntp_service ; then if [[ -z "$ntp_allowed_net" ]] ; then echo_failed else diff --git a/ipt-firewall-server b/ipt-firewall-server index 3623c60..741d8a1 100755 --- a/ipt-firewall-server +++ b/ipt-firewall-server @@ -1282,6 +1282,23 @@ else fi +# --- +# - local Resolver" +# --- + +echononl "\t\tlocal Resolver" +if [[ -n "$local_resolver_service" ]] && $local_resolver_service ; then + if [[ -z "$resolver_allowed_net" ]] ; then + echo_failed + else + $ipt -A INPUT -p udp -s $resolver_allowed_net --dport $resolver_port -m conntrack --ctstate NEW -j ACCEPT + echo_done + fi +else + echo_skipped +fi + + # --- # - SSH out only # --- @@ -1934,7 +1951,7 @@ echo_done # --- echononl "\t\tNTP local Service" -if [[ -n $local_ntp_service ]] && $local_ntp_service ; then +if [[ -n "$local_ntp_service" ]] && $local_ntp_service ; then if [[ -z "$ntp_allowed_net" ]] ; then echo_failed else