From fc7f18a85a004d795f1d466bdc9136964819519a Mon Sep 17 00:00:00 2001 From: ficus Date: Thu, 22 Nov 2012 17:00:48 +0100 Subject: move tor-wireless-firewall.sh to expected location --- config/includes.chroot/sbin/tor-wireless-firewall.sh | 20 -------------------- .../usr/sbin/tor-wireless-firewall.sh | 20 ++++++++++++++++++++ 2 files changed, 20 insertions(+), 20 deletions(-) delete mode 100755 config/includes.chroot/sbin/tor-wireless-firewall.sh create mode 100755 config/includes.chroot/usr/sbin/tor-wireless-firewall.sh diff --git a/config/includes.chroot/sbin/tor-wireless-firewall.sh b/config/includes.chroot/sbin/tor-wireless-firewall.sh deleted file mode 100755 index 4310e7b..0000000 --- a/config/includes.chroot/sbin/tor-wireless-firewall.sh +++ /dev/null @@ -1,20 +0,0 @@ -#!/bin/sh - -# destinations you don't want routed through Tor -NON_TOR="10.0.2.0/24 10.23.42.0/24 172.16.23.0/24" - -# Tor's TransPort -TRANS_PORT="9040" - -# your internal interface -INT_IF="uap0" - -iptables -F -iptables -t nat -F - -for NET in $NON_TOR; do - iptables -t nat -A PREROUTING -i $INT_IF -d $NET -j RETURN -done -iptables -t nat -A PREROUTING -i $INT_IF -p udp --dport 53 -j REDIRECT --to-ports 5353 -#iptables -t nat -A PREROUTING -i $INT_IF -p udp --dport 67 -j REDIRECT --to-ports 67 -iptables -t nat -A PREROUTING -i $INT_IF -p tcp --syn -j REDIRECT --to-ports $TRANS_PORT diff --git a/config/includes.chroot/usr/sbin/tor-wireless-firewall.sh b/config/includes.chroot/usr/sbin/tor-wireless-firewall.sh new file mode 100755 index 0000000..4310e7b --- /dev/null +++ b/config/includes.chroot/usr/sbin/tor-wireless-firewall.sh @@ -0,0 +1,20 @@ +#!/bin/sh + +# destinations you don't want routed through Tor +NON_TOR="10.0.2.0/24 10.23.42.0/24 172.16.23.0/24" + +# Tor's TransPort +TRANS_PORT="9040" + +# your internal interface +INT_IF="uap0" + +iptables -F +iptables -t nat -F + +for NET in $NON_TOR; do + iptables -t nat -A PREROUTING -i $INT_IF -d $NET -j RETURN +done +iptables -t nat -A PREROUTING -i $INT_IF -p udp --dport 53 -j REDIRECT --to-ports 5353 +#iptables -t nat -A PREROUTING -i $INT_IF -p udp --dport 67 -j REDIRECT --to-ports 67 +iptables -t nat -A PREROUTING -i $INT_IF -p tcp --syn -j REDIRECT --to-ports $TRANS_PORT -- cgit v1.2.3