diff --git a/roles/exit_ip/templates/rules.v4.j2 b/roles/exit_ip/templates/rules.v4.j2 index 87b9150..63d0dd0 100644 --- a/roles/exit_ip/templates/rules.v4.j2 +++ b/roles/exit_ip/templates/rules.v4.j2 @@ -8,8 +8,10 @@ COMMIT *filter :INPUT ACCEPT [1124:131621] --A INPUT -p udp -m multiport -i br-{{ site_code }} --destination-ports {{ fastd_port }}:{{ fastd_port + (fastd_instances-1) }} -j LOG --log-prefix "vpn-int-loop-" -m limit --limit 5/min +-A INPUT -p udp -m multiport -i br-{{ site_code }} --destination-ports {{ fastd_port }}:{{ fastd_port + (fastd_instances-1) }} -j LOG --log-prefix "fastd-vpn-int-loop-" -m limit --limit 5/min -A INPUT -p udp -m multiport -i br-{{ site_code }} --destination-ports {{ fastd_port }}:{{ fastd_port + (fastd_instances-1) }} -j REJECT +-A INPUT -p udp -i br-{{ site_code }} --dport {{ mesh_wg_port }} -j LOG --log-prefix "wg-vpn-int-loop-" -m limit --limit 5/min +-A INPUT -p udp -i br-{{ site_code }} --dport {{ mesh_wg_port }} -j REJECT :FORWARD ACCEPT [0:0] -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu :OUTPUT ACCEPT [1151:175226] diff --git a/roles/exit_ip/templates/rules.v6.j2 b/roles/exit_ip/templates/rules.v6.j2 index 155a479..d2dcf1a 100644 --- a/roles/exit_ip/templates/rules.v6.j2 +++ b/roles/exit_ip/templates/rules.v6.j2 @@ -3,6 +3,8 @@ :INPUT ACCEPT [0:0] -A INPUT -p udp -m multiport -i br-{{ site_code }} --destination-ports {{ fastd_port }}:{{ fastd_port + (fastd_instances-1) }} -j LOG --log-prefix "vpn-int-loop-" -m limit --limit 5/min -A INPUT -p udp -m multiport -i br-{{ site_code }} --destination-ports {{ fastd_port }}:{{ fastd_port + (fastd_instances-1) }} -j REJECT +-A INPUT -p udp -i br-{{ site_code }} --dport {{ mesh_wg_port }} -j LOG --log-prefix "wg-vpn-int-loop-" -m limit --limit 5/min +-A INPUT -p udp -i br-{{ site_code }} --dport {{ mesh_wg_port }} -j REJECT :FORWARD ACCEPT [0:0] -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu :OUTPUT ACCEPT [0:0]