diff --git a/gestion/gen_confs/firewall.py b/gestion/gen_confs/firewall.py index d6850dc1..56cb30b4 100755 --- a/gestion/gen_confs/firewall.py +++ b/gestion/gen_confs/firewall.py @@ -695,18 +695,12 @@ class firewall_komaz(firewall_crans) : # On ne filtre que ce qui passe sur l'interface externe iptables('-A FILTRE_P2P -i %s -o %s -j RETURN' % (self.eth_int, self.eth_int) ) - for port in self.ports_p2p : - #iptables('-A FILTRE_P2P -p tcp --dport %s -j REJECT --reject-with icmp-admin-prohibited' % port ) - iptables('-A FILTRE_P2P -p tcp --dport %s -j ACCEPT' % port) - #iptables('-A FILTRE_P2P -p udp --dport %s -j REJECT --reject-with icmp-admin-prohibited' % port ) - iptables('-A FILTRE_P2P -p udp --dport %s -j ACCEPT' % port ) - self.anim.cycle() for filtre in self.filtres_p2p : iptables('-A FILTRE_P2P -m ipp2p --%s -j LOG --log-prefix "IPP2P=%s "' % (filtre[0], filtre[1])) #iptables('-A FILTRE_P2P -m ipp2p --%s -j REJECT --reject-with icmp-admin-prohibited' % filtre[0]) - iptables('-A FILTRE_P2P -m ipp2p --%s -j ACCEPT' % filtre[0]) + iptables('-A FILTRE_P2P -m ipp2p --%s -j RETURN' % filtre[0]) self.anim.cycle() self.anim.reinit()