From 27431ddc894d1b2ce91e5fdd68932d97d35238f7 Mon Sep 17 00:00:00 2001 From: bogale Date: Sat, 26 Sep 2026 23:56:49 +0900 Subject: [PATCH] dport and port differentiation --- .gitignore | 1 - data/dest.env | 2 +- data/install.sh | 33 +++++++++++++++++++++++---------- 3 files changed, 24 insertions(+), 12 deletions(-) diff --git a/.gitignore b/.gitignore index 9325819..877d3ce 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1 @@ -/local /data/awg0.conf diff --git a/data/dest.env b/data/dest.env index 270be91..f3416c6 100644 --- a/data/dest.env +++ b/data/dest.env @@ -1,2 +1,2 @@ -DEST=10.0.0.2 DEST6=fc00::2 +DEST4=10.0.0.2 diff --git a/data/install.sh b/data/install.sh index 7fe71c6..c06db9d 100755 --- a/data/install.sh +++ b/data/install.sh @@ -2,27 +2,40 @@ set -euo pipefail . data/dest.env cat <> /etc/sysctl.conf +net.ipv6.conf.all.forwarding = 1 net.ipv4.ip_forward = 1 net.ipv4.conf.all.forwarding = 1 -net.ipv6.conf.all.forwarding = 1 EOF -for v in "" 6; do +for v in 6 ""; do ip${v}tables -P FORWARD DROP ip${v}tables -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT ip${v}tables -A FORWARD -i awg0 -j ACCEPT ip${v}tables -t nat -A POSTROUTING -o eth0 -j MASQUERADE done -for route in tcp:25 tcp:80 tcp:443 udp:443; do - PROTO=${route%:*} - PORT=${route#*:} - iptables -t nat -A PREROUTING -m addrtype --dst-type LOCAL -p $PROTO --dport $PORT -j DNAT --to-destination $DEST:$PORT - iptables -A FORWARD -d $DEST -p $PROTO --dport $PORT -j ACCEPT - ip6tables -t nat -A PREROUTING -m addrtype --dst-type LOCAL -p $PROTO --dport $PORT -j DNAT --to-destination [$DEST6]:$PORT - ip6tables -A FORWARD -d $DEST6 -p $PROTO --dport $PORT -j ACCEPT +for sock in tcp:25 80 443 2235=22 udp:443; do + if [[ "$sock" == *:* ]]; then + PORT=${sock#*:} + PROTO=${sock%:*} + else + PORT=$sock + fi + if [[ "$PORT" == *=* ]]; then + DPORT=${PORT#*=} + PORT=${PORT%=*} + else + DPORT=$PORT + fi + ip6tables -t nat -A PREROUTING -m addrtype --dst-type LOCAL \ + -p $PROTO --dport $PORT -j DNAT --to-destination [$DEST6]:$DPORT + ip6tables -A FORWARD -d $DEST6 -p $PROTO --dport $DPORT -j ACCEPT + iptables -t nat -A PREROUTING -m addrtype --dst-type LOCAL \ + -p $PROTO --dport $PORT -j DNAT --to-destination $DEST4:$DPORT + iptables -A FORWARD -d $DEST4 -p $PROTO --dport $DPORT -j ACCEPT done export DEBIAN_FRONTEND=noninteractive add-apt-repository -y ppa:amnezia/ppa -apt-get install -y software-properties-common python3-launchpadlib gnupg2 linux-headers-$(uname -r) amneziawg amneziawg-tools iptables-persistent +apt-get install -y software-properties-common python3-launchpadlib gnupg2 \ + linux-headers-$(uname -r) amneziawg amneziawg-tools iptables-persistent mv data/awg0.conf /etc/amnezia/amneziawg systemctl enable awg-quick@awg0 apt-get autoremove --purge -y