Quantcast
Channel: Tomato Firmware
Viewing all articles
Browse latest Browse all 5181

Killswitch

$
0
0
Using the following kill switch in scripts firewall

WAN_IF=`nvram get wan_iface`
iptables -I FORWARD -i br0 -o $WAN_IF -j REJECT --reject-with icmp-host-prohibited
iptables -I FORWARD -i br0 -p tcp -o $WAN_IF -j REJECT --reject-with tcp-reset
iptables -I FORWARD -i br0 -p udp -o $WAN_IF -j REJECT --reject-with udp-reset

Is this overkill and can I just use the following?
iptables -I FORWARD -i br0 -o `nvram get wan_iface` -j DROP

Viewing all articles
Browse latest Browse all 5181

Trending Articles