Project

General

Profile

Snippets » History » Version 3

Pau Escrich, 04/23/2014 12:27 PM

1 1 Pau Escrich
h1. Snippets
2 1 Pau Escrich
3 1 Pau Escrich
h3. Gateways
4 1 Pau Escrich
5 1 Pau Escrich
Disable the gateway checker and force a node to publish Internet in the network.
6 1 Pau Escrich
<pre>
7 1 Pau Escrich
/etc/init.d/gwck stop
8 1 Pau Escrich
/etc/init.d/gwck disable
9 1 Pau Escrich
killall -9 gwck
10 1 Pau Escrich
uci set qmp.services.gwck=0
11 1 Pau Escrich
uci commit
12 1 Pau Escrich
13 1 Pau Escrich
uci set gateways.inet4_offer.ignore=0
14 1 Pau Escrich
uci set gateways.inet4.ignore=1
15 1 Pau Escrich
uci commit
16 1 Pau Escrich
qmpcontrol configure_gw
17 1 Pau Escrich
</pre>
18 2 Pau Escrich
19 2 Pau Escrich
h3. Firewall
20 3 Pau Escrich
21 2 Pau Escrich
For those nodes connected directly to Internet you may want to configure a set of firewall rules. This is an example which must be adapted to each situation.
22 2 Pau Escrich
They should be added to the file /etc/firewall.user
23 2 Pau Escrich
24 2 Pau Escrich
<pre>
25 2 Pau Escrich
# Firewall
26 2 Pau Escrich
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
27 2 Pau Escrich
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
28 2 Pau Escrich
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
29 2 Pau Escrich
iptables -A INPUT -s 127.0.0.0/8 -j ACCEPT
30 2 Pau Escrich
iptables -A INPUT -s 172.16.0.0/12 -j ACCEPT
31 2 Pau Escrich
iptables -A INPUT -s 192.168.0.0/16 -j ACCEPT
32 2 Pau Escrich
iptables -A INPUT -s 10.0.0.0/8 -j ACCEPT
33 2 Pau Escrich
iptables -A INPUT -p udp --dport 67 -j ACCEPT
34 2 Pau Escrich
iptables -A INPUT -p udp --dport 68 -j ACCEPT
35 2 Pau Escrich
iptables -P INPUT DROP
36 2 Pau Escrich
iptables -P OUTPUT ACCEPT
37 2 Pau Escrich
</pre>