From 9f3c4a2381d49da736cab45435777525d96f22a8 Mon Sep 17 00:00:00 2001 From: tv Date: Sat, 18 Jul 2015 12:34:18 +0200 Subject: 3 tv.iptables: unique ports --- 3modules/tv/iptables.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to '3modules/tv/iptables.nix') diff --git a/3modules/tv/iptables.nix b/3modules/tv/iptables.nix index 7b9edd38..21cf7732 100644 --- a/3modules/tv/iptables.nix +++ b/3modules/tv/iptables.nix @@ -76,7 +76,7 @@ let "-m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT" "-i lo -j ACCEPT" ] - ++ map accept-new-tcp cfg.input-internet-accept-new-tcp + ++ map accept-new-tcp (unique cfg.input-internet-accept-new-tcp) ++ ["-i retiolum -j Retiolum"] )} ${concatMapStringsSep "\n" (rule: "-A Retiolum ${rule}") ([] @@ -88,7 +88,7 @@ let "-p ipv6-icmp -m icmp6 --icmpv6-type echo-request -j ACCEPT" ]; }."ip${toString iptables-version}tables" - ++ map accept-new-tcp cfg.input-retiolum-accept-new-tcp + ++ map accept-new-tcp (unique cfg.input-retiolum-accept-new-tcp) ++ { ip4tables = [ "-p tcp -j REJECT --reject-with tcp-reset" -- cgit v1.2.3