瀏覽代碼

gluon-core: firewall: make the default input policy REJECT

Fixes #1311
Matthias Schiffer 6 年之前
父節點
當前提交
01336f70ec
共有 1 個文件被更改,包括 4 次插入0 次删除
  1. 4 0
      package/gluon-core/luasrc/lib/gluon/upgrade/140-firewall-rules

+ 4 - 0
package/gluon-core/luasrc/lib/gluon/upgrade/140-firewall-rules

@@ -3,6 +3,10 @@
 local uci = require('simple-uci').cursor()
 
 
+local defaults = uci:get_first('firewall', 'defaults')
+uci:set('firewall', defaults, 'input', 'REJECT')
+
+
 local function reject_input_on_wan(zone)
 	if zone.name == 'wan' then
 		uci:set('firewall', zone['.name'], 'input', 'REJECT')