dport and port differentiation
This commit is contained in:
parent
0383cfd0d8
commit
27431ddc89
3 changed files with 24 additions and 12 deletions
1
.gitignore
vendored
1
.gitignore
vendored
|
|
@ -1,2 +1 @@
|
||||||
/local
|
|
||||||
/data/awg0.conf
|
/data/awg0.conf
|
||||||
|
|
|
||||||
|
|
@ -1,2 +1,2 @@
|
||||||
DEST=10.0.0.2
|
|
||||||
DEST6=fc00::2
|
DEST6=fc00::2
|
||||||
|
DEST4=10.0.0.2
|
||||||
|
|
|
||||||
|
|
@ -2,27 +2,40 @@
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
. data/dest.env
|
. data/dest.env
|
||||||
cat <<EOF >> /etc/sysctl.conf
|
cat <<EOF >> /etc/sysctl.conf
|
||||||
|
net.ipv6.conf.all.forwarding = 1
|
||||||
net.ipv4.ip_forward = 1
|
net.ipv4.ip_forward = 1
|
||||||
net.ipv4.conf.all.forwarding = 1
|
net.ipv4.conf.all.forwarding = 1
|
||||||
net.ipv6.conf.all.forwarding = 1
|
|
||||||
EOF
|
EOF
|
||||||
for v in "" 6; do
|
for v in 6 ""; do
|
||||||
ip${v}tables -P FORWARD DROP
|
ip${v}tables -P FORWARD DROP
|
||||||
ip${v}tables -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
ip${v}tables -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||||
ip${v}tables -A FORWARD -i awg0 -j ACCEPT
|
ip${v}tables -A FORWARD -i awg0 -j ACCEPT
|
||||||
ip${v}tables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
|
ip${v}tables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
|
||||||
done
|
done
|
||||||
for route in tcp:25 tcp:80 tcp:443 udp:443; do
|
for sock in tcp:25 80 443 2235=22 udp:443; do
|
||||||
PROTO=${route%:*}
|
if [[ "$sock" == *:* ]]; then
|
||||||
PORT=${route#*:}
|
PORT=${sock#*:}
|
||||||
iptables -t nat -A PREROUTING -m addrtype --dst-type LOCAL -p $PROTO --dport $PORT -j DNAT --to-destination $DEST:$PORT
|
PROTO=${sock%:*}
|
||||||
iptables -A FORWARD -d $DEST -p $PROTO --dport $PORT -j ACCEPT
|
else
|
||||||
ip6tables -t nat -A PREROUTING -m addrtype --dst-type LOCAL -p $PROTO --dport $PORT -j DNAT --to-destination [$DEST6]:$PORT
|
PORT=$sock
|
||||||
ip6tables -A FORWARD -d $DEST6 -p $PROTO --dport $PORT -j ACCEPT
|
fi
|
||||||
|
if [[ "$PORT" == *=* ]]; then
|
||||||
|
DPORT=${PORT#*=}
|
||||||
|
PORT=${PORT%=*}
|
||||||
|
else
|
||||||
|
DPORT=$PORT
|
||||||
|
fi
|
||||||
|
ip6tables -t nat -A PREROUTING -m addrtype --dst-type LOCAL \
|
||||||
|
-p $PROTO --dport $PORT -j DNAT --to-destination [$DEST6]:$DPORT
|
||||||
|
ip6tables -A FORWARD -d $DEST6 -p $PROTO --dport $DPORT -j ACCEPT
|
||||||
|
iptables -t nat -A PREROUTING -m addrtype --dst-type LOCAL \
|
||||||
|
-p $PROTO --dport $PORT -j DNAT --to-destination $DEST4:$DPORT
|
||||||
|
iptables -A FORWARD -d $DEST4 -p $PROTO --dport $DPORT -j ACCEPT
|
||||||
done
|
done
|
||||||
export DEBIAN_FRONTEND=noninteractive
|
export DEBIAN_FRONTEND=noninteractive
|
||||||
add-apt-repository -y ppa:amnezia/ppa
|
add-apt-repository -y ppa:amnezia/ppa
|
||||||
apt-get install -y software-properties-common python3-launchpadlib gnupg2 linux-headers-$(uname -r) amneziawg amneziawg-tools iptables-persistent
|
apt-get install -y software-properties-common python3-launchpadlib gnupg2 \
|
||||||
|
linux-headers-$(uname -r) amneziawg amneziawg-tools iptables-persistent
|
||||||
mv data/awg0.conf /etc/amnezia/amneziawg
|
mv data/awg0.conf /etc/amnezia/amneziawg
|
||||||
systemctl enable awg-quick@awg0
|
systemctl enable awg-quick@awg0
|
||||||
apt-get autoremove --purge -y
|
apt-get autoremove --purge -y
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue