|
|
@ -4,13 +4,13 @@
|
|
|
|
:FORWARD ACCEPT [0:0]
|
|
|
|
:FORWARD ACCEPT [0:0]
|
|
|
|
:OUTPUT ACCEPT [0:0]
|
|
|
|
:OUTPUT ACCEPT [0:0]
|
|
|
|
:POSTROUTING ACCEPT [0:0]
|
|
|
|
:POSTROUTING ACCEPT [0:0]
|
|
|
|
{% if 'fastd' in group_names %}
|
|
|
|
{% if 'fastd' in group_names or 'wg' in group_names %}
|
|
|
|
{% for site in sites %}
|
|
|
|
{% for site in sites %}
|
|
|
|
-A PREROUTING -i bat{{ site.name }} -j MARK --set-xmark 0x1/0xffffffff
|
|
|
|
-A PREROUTING -i bat{{ site.name }} -j MARK --set-xmark 0x1/0xffffffff
|
|
|
|
{% endfor %}
|
|
|
|
{% endfor %}
|
|
|
|
{% endif %}
|
|
|
|
{% endif %}
|
|
|
|
|
|
|
|
|
|
|
|
{% if 'fastd' in group_names %}
|
|
|
|
{% if 'fastd' in group_names or 'wg' in group_names %}
|
|
|
|
{% for peer in groups['uplink'] %}
|
|
|
|
{% for peer in groups['uplink'] %}
|
|
|
|
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff
|
|
|
|
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff
|
|
|
|
{% endfor %}
|
|
|
|
{% endfor %}
|
|
|
@ -19,6 +19,9 @@
|
|
|
|
{% for peer in groups['fastd'] %}
|
|
|
|
{% for peer in groups['fastd'] %}
|
|
|
|
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff
|
|
|
|
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff
|
|
|
|
{% endfor %}
|
|
|
|
{% endfor %}
|
|
|
|
|
|
|
|
{% for peer in groups['wg'] %}
|
|
|
|
|
|
|
|
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff
|
|
|
|
|
|
|
|
{% endfor %}
|
|
|
|
{% for peer in groups['uplink'] | difference([inventory_hostname]) %}
|
|
|
|
{% for peer in groups['uplink'] | difference([inventory_hostname]) %}
|
|
|
|
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff
|
|
|
|
-A PREROUTING -i bb{{ hostvars[peer]['wireguard_bb_name'] }} ! -s fe80::/64 ! -d fe80::/64 -j MARK --set-xmark 0x1/0xffffffff
|
|
|
|
{% endfor %}
|
|
|
|
{% endfor %}
|
|
|
@ -42,15 +45,24 @@ COMMIT
|
|
|
|
# iperf3
|
|
|
|
# iperf3
|
|
|
|
-A INPUT -p tcp -m tcp -s 2a03:2260:1016::/48 --dport 5201 -j ACCEPT
|
|
|
|
-A INPUT -p tcp -m tcp -s 2a03:2260:1016::/48 --dport 5201 -j ACCEPT
|
|
|
|
|
|
|
|
|
|
|
|
{% if 'fastd' in group_names %}
|
|
|
|
{% if 'fastd' in group_names or 'wg' in group_names %}
|
|
|
|
# dns
|
|
|
|
# dns
|
|
|
|
-A INPUT -p tcp -m tcp --dport 53 -j ACCEPT
|
|
|
|
-A INPUT -p tcp -m tcp --dport 53 -j ACCEPT
|
|
|
|
-A INPUT -p udp -m udp --dport 53 -j ACCEPT
|
|
|
|
-A INPUT -p udp -m udp --dport 53 -j ACCEPT
|
|
|
|
# ntp
|
|
|
|
# ntp
|
|
|
|
-A INPUT -p udp -m udp --dport 123 -j ACCEPT
|
|
|
|
-A INPUT -p udp -m udp --dport 123 -j ACCEPT
|
|
|
|
|
|
|
|
{% endif %}
|
|
|
|
|
|
|
|
{% if 'fastd' in group_names %}
|
|
|
|
# fastd
|
|
|
|
# fastd
|
|
|
|
-A INPUT -s 2a03:2260:1016::/48 -p udp -m udp --dport 10010:10023 -j DROP
|
|
|
|
-A INPUT -s 2a03:2260:1016::/48 -p udp -m udp --dport 10010:10023 -j DROP
|
|
|
|
-A INPUT -p udp -m udp --dport 10010:10023 -j ACCEPT
|
|
|
|
-A INPUT -p udp -m udp --dport 10010:10023 -j ACCEPT
|
|
|
|
|
|
|
|
{% endif %}
|
|
|
|
|
|
|
|
{% if 'wg' in group_names %}
|
|
|
|
|
|
|
|
# wg
|
|
|
|
|
|
|
|
-A INPUT -s 2a03:2260:1016::/48 -p udp -m udp --dport 10000 -j DROP
|
|
|
|
|
|
|
|
-A INPUT -p udp -m udp --dport 10000 -j ACCEPT
|
|
|
|
|
|
|
|
{% endif %}
|
|
|
|
|
|
|
|
{% if 'fastd' in group_names or 'wg' in group_names %}
|
|
|
|
# respondd
|
|
|
|
# respondd
|
|
|
|
-A INPUT -i bat+ -p udp -m udp --dport 1001 -j ACCEPT
|
|
|
|
-A INPUT -i bat+ -p udp -m udp --dport 1001 -j ACCEPT
|
|
|
|
# wireguard_mesh
|
|
|
|
# wireguard_mesh
|
|
|
@ -60,7 +72,7 @@ COMMIT
|
|
|
|
{% endfor %}
|
|
|
|
{% endfor %}
|
|
|
|
{% endif %}
|
|
|
|
{% endif %}
|
|
|
|
# wireguard_backbone
|
|
|
|
# wireguard_backbone
|
|
|
|
{% if 'fastd' in group_names %}
|
|
|
|
{% if 'fastd' in group_names or 'wg' in group_names %}
|
|
|
|
{% for peer in groups['uplink'] %}
|
|
|
|
{% for peer in groups['uplink'] %}
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
-A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT
|
|
|
|
-A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT
|
|
|
@ -71,6 +83,10 @@ COMMIT
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
-A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT
|
|
|
|
-A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT
|
|
|
|
{% endfor %}
|
|
|
|
{% endfor %}
|
|
|
|
|
|
|
|
{% for peer in groups['wg'] %}
|
|
|
|
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
|
|
|
|
-A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT
|
|
|
|
|
|
|
|
{% endfor %}
|
|
|
|
{% for peer in groups['uplink'] | difference([inventory_hostname]) %}
|
|
|
|
{% for peer in groups['uplink'] | difference([inventory_hostname]) %}
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
-A INPUT -i bb{{ hostvars[peer]['wireguard_bb_name'] }} -p udp --dport 6696 -j ACCEPT
|
|
|
|
-A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT
|
|
|
|
-A INPUT -p udp --dport {{ hostvars[peer]['wireguard_bb_port'] }} -j ACCEPT
|
|
|
@ -92,8 +108,9 @@ COMMIT
|
|
|
|
# LOG
|
|
|
|
# LOG
|
|
|
|
-A INPUT -m limit --limit 2/min -j LOG --log-prefix "IP6Tables-Dropped input: " --log-level 4
|
|
|
|
-A INPUT -m limit --limit 2/min -j LOG --log-prefix "IP6Tables-Dropped input: " --log-level 4
|
|
|
|
|
|
|
|
|
|
|
|
{% if 'fastd' in group_names %}
|
|
|
|
{% if 'fastd' in group_names or 'wg' in group_names %}
|
|
|
|
{% for site in sites %}
|
|
|
|
{% for site in sites %}
|
|
|
|
|
|
|
|
-A FORWARD -i bat{{ site.name }} -p udp --dport 10000 -j REJECT
|
|
|
|
-A FORWARD -i bat{{ site.name }} -p udp --dport 10010:10021 -j REJECT
|
|
|
|
-A FORWARD -i bat{{ site.name }} -p udp --dport 10010:10021 -j REJECT
|
|
|
|
{% endfor %}
|
|
|
|
{% endfor %}
|
|
|
|
{% endif %}
|
|
|
|
{% endif %}
|
|
|
|