Add git, neofetch, replace iptables with nftables, setup /etc/sysctl.conf
This commit is contained in:
parent
a43e95b17f
commit
8202f22735
5 changed files with 133 additions and 18 deletions
49
board/mentalnet/overlay/etc/init.d/S35nftables
Executable file
49
board/mentalnet/overlay/etc/init.d/S35nftables
Executable file
|
|
@ -0,0 +1,49 @@
|
|||
#!/bin/sh
|
||||
#
|
||||
# Load the nftables firewall ruleset from /etc/nftables.conf.
|
||||
|
||||
DAEMON="nft"
|
||||
CONF="/etc/nftables.conf"
|
||||
|
||||
start() {
|
||||
printf 'Loading nftables firewall: '
|
||||
if ! [ -f "$CONF" ]; then
|
||||
echo "MISSING $CONF"
|
||||
return 1
|
||||
fi
|
||||
"$DAEMON" -f "$CONF"
|
||||
status=$?
|
||||
if [ "$status" -eq 0 ]; then
|
||||
echo "OK"
|
||||
else
|
||||
echo "FAIL"
|
||||
fi
|
||||
return "$status"
|
||||
}
|
||||
|
||||
stop() {
|
||||
printf 'Flushing nftables ruleset: '
|
||||
"$DAEMON" flush ruleset
|
||||
status=$?
|
||||
if [ "$status" -eq 0 ]; then
|
||||
echo "OK"
|
||||
else
|
||||
echo "FAIL"
|
||||
fi
|
||||
return "$status"
|
||||
}
|
||||
|
||||
restart() {
|
||||
stop
|
||||
start
|
||||
}
|
||||
|
||||
case "$1" in
|
||||
start|stop|restart)
|
||||
"$1";;
|
||||
reload)
|
||||
restart;;
|
||||
*)
|
||||
echo "Usage: $0 {start|stop|restart|reload}"
|
||||
exit 1
|
||||
esac
|
||||
41
board/mentalnet/overlay/etc/nftables.conf
Normal file
41
board/mentalnet/overlay/etc/nftables.conf
Normal file
|
|
@ -0,0 +1,41 @@
|
|||
# /etc/nftables.conf - Mentalnet GNU/Linux firewall
|
||||
# Loaded by /etc/init.d/S35nftables at boot. Edit and re-run:
|
||||
# nft -f /etc/nftables.conf
|
||||
|
||||
flush ruleset
|
||||
|
||||
table inet filter {
|
||||
chain input {
|
||||
type filter hook input priority 0; policy drop;
|
||||
|
||||
# loopback
|
||||
iifname "lo" accept
|
||||
|
||||
# established and related connections
|
||||
ct state established,related accept
|
||||
|
||||
# DHCP client replies
|
||||
udp sport 67 udp dport 68 accept
|
||||
|
||||
# ICMP (ping et al.)
|
||||
ip protocol icmp accept
|
||||
ip6 nexthdr icmpv6 accept
|
||||
|
||||
# services: SSH, HTTP
|
||||
tcp dport 22 accept
|
||||
tcp dport 80 accept
|
||||
|
||||
# log and reject everything else (rate-limited: goes to
|
||||
# syslog, not the TTY - see /etc/sysctl.conf)
|
||||
limit rate 1/minute log prefix "nft-drop: " counter
|
||||
counter reject with icmpx type port-unreachable
|
||||
}
|
||||
|
||||
chain forward {
|
||||
type filter hook forward priority 0; policy accept;
|
||||
}
|
||||
|
||||
chain output {
|
||||
type filter hook output priority 0; policy accept;
|
||||
}
|
||||
}
|
||||
6
board/mentalnet/overlay/etc/sysctl.conf
Normal file
6
board/mentalnet/overlay/etc/sysctl.conf
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
# /etc/sysctl.conf - Mentalnet GNU/Linux runtime kernel settings
|
||||
# Applied by /etc/init.d/S02sysctl at boot.
|
||||
|
||||
# Keep the TTY quiet: console shows errors and worse only.
|
||||
# Kernel warnings (e.g. nft-drop lines) still reach syslog via klogd.
|
||||
kernel.printk = 3 4 1 3
|
||||
Loading…
Add table
Add a link
Reference in a new issue