fix
This commit is contained in:
parent
ba9d56c88e
commit
945e1bbd40
27
firewall.sh
27
firewall.sh
@ -4,7 +4,7 @@ MY_IP=($(redis-cli --raw SMEMBERS my_ip))
|
|||||||
ATTACK_THRESHOLD="50"
|
ATTACK_THRESHOLD="50"
|
||||||
NGINX_ACCESS="/tmp/access.log"
|
NGINX_ACCESS="/tmp/access.log"
|
||||||
ACCESS="/tmp/minute.log"
|
ACCESS="/tmp/minute.log"
|
||||||
HTTP_LIMIT="100"
|
HTTP_LIMIT="200"
|
||||||
RATE_LIMITED_HTTP="30"
|
RATE_LIMITED_HTTP="30"
|
||||||
MODULES="/opt/firewall/modules"
|
MODULES="/opt/firewall/modules"
|
||||||
TMP_BLOCK_TIMEOUT="20"
|
TMP_BLOCK_TIMEOUT="20"
|
||||||
@ -180,23 +180,16 @@ import-saved() {
|
|||||||
|
|
||||||
start() {
|
start() {
|
||||||
basic-security
|
basic-security
|
||||||
|
sysctl -w net.ipv4.conf.all.forwarding=1
|
||||||
|
import-saved
|
||||||
|
blockCountry
|
||||||
|
wireguard-networking
|
||||||
|
docker restart uptime-kuma
|
||||||
|
#Docker
|
||||||
|
$NFT insert rule filter input iif docker0 accept
|
||||||
|
|
||||||
if [[ $HOSTNAME == *"nas"* ]]; then
|
#HTTP Rate Limit
|
||||||
sysctl -w net.ipv4.conf.all.forwarding=1
|
bash $MODULES/module-rate-limit-web.sh $HTTP_LIMIT
|
||||||
import-saved
|
|
||||||
blockCountry
|
|
||||||
wireguard-networking
|
|
||||||
docker restart uptime-kuma
|
|
||||||
|
|
||||||
#Docker
|
|
||||||
$NFT insert rule filter input iif docker0 accept
|
|
||||||
|
|
||||||
#HTTP Rate Limit
|
|
||||||
bash $MODULES/module-rate-limit-web.sh $HTTP_LIMIT
|
|
||||||
|
|
||||||
else
|
|
||||||
virtualization
|
|
||||||
fi
|
|
||||||
message "Starting Firewall"
|
message "Starting Firewall"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user