添加防火墙
This commit is contained in:
+187
-1
@@ -545,4 +545,190 @@ for i in "${!RELAY_DOMAINS[@]}"; do
|
||||
fi
|
||||
echo ""
|
||||
done
|
||||
success "Setup complete! 🎉"
|
||||
success "Setup complete! 🎉"
|
||||
|
||||
# ═════════════════════════════════════════════════════════════════════════════
|
||||
# STEP 6 – Firewall (optional)
|
||||
# ═════════════════════════════════════════════════════════════════════════════
|
||||
header "Step 6 · Firewall Configuration (optional)"
|
||||
|
||||
$DRY_RUN && { warn "DRY-RUN: skipping firewall step."; exit 0; }
|
||||
|
||||
if ! ask_yn "Configure firewall rules now?" "y"; then
|
||||
info "Skipped. Remember to open the ports listed above manually."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# ── Detect firewall ───────────────────────────────────────────────────────────
|
||||
detect_firewall() {
|
||||
if systemctl is-active --quiet firewalld 2>/dev/null; then
|
||||
echo "firewalld"
|
||||
elif systemctl is-active --quiet ufw 2>/dev/null || command -v ufw &>/dev/null && ufw status 2>/dev/null | grep -q "Status: active"; then
|
||||
echo "ufw"
|
||||
elif command -v nft &>/dev/null && nft list ruleset 2>/dev/null | grep -q "table"; then
|
||||
echo "nftables"
|
||||
elif command -v iptables &>/dev/null; then
|
||||
echo "iptables"
|
||||
else
|
||||
echo "none"
|
||||
fi
|
||||
}
|
||||
|
||||
FW="$(detect_firewall)"
|
||||
|
||||
case "$FW" in
|
||||
firewalld) info "Detected: firewalld" ;;
|
||||
ufw) info "Detected: ufw" ;;
|
||||
nftables) info "Detected: nftables" ;;
|
||||
iptables) info "Detected: iptables" ;;
|
||||
none) warn "No supported firewall detected (firewalld / ufw / nftables / iptables)."
|
||||
info "Open the ports listed in Step 5 manually."
|
||||
exit 0 ;;
|
||||
esac
|
||||
|
||||
# ── Collect all ports to open across all relays ───────────────────────────────
|
||||
declare -a FW_TCP=()
|
||||
declare -a FW_UDP=()
|
||||
|
||||
for i in "${!RELAY_DOMAINS[@]}"; do
|
||||
LP="${RELAY_LISTEN_PORTS[$i]}"
|
||||
TM="${RELAY_TLS_MODES[$i]}"
|
||||
ES="${RELAY_ENABLE_STUN[$i]}"
|
||||
SP="${RELAY_STUN_PORTS_LIST[$i]}"
|
||||
|
||||
# TCP: relay port
|
||||
FW_TCP+=("$LP")
|
||||
# TCP: port 80 for Let's Encrypt
|
||||
[[ "$TM" == "1" ]] && FW_TCP+=("80")
|
||||
# UDP: STUN ports
|
||||
if [[ "$ES" == "true" ]] && [[ -n "$SP" ]]; then
|
||||
IFS=',' read -ra _SP <<< "$SP"
|
||||
for _P in "${_SP[@]}"; do
|
||||
FW_UDP+=("${_P// /}")
|
||||
done
|
||||
fi
|
||||
done
|
||||
|
||||
# Deduplicate
|
||||
mapfile -t FW_TCP < <(printf '%s\n' "${FW_TCP[@]}" | sort -un)
|
||||
mapfile -t FW_UDP < <(printf '%s\n' "${FW_UDP[@]}" | sort -un)
|
||||
|
||||
echo ""
|
||||
echo -e "${BOLD}Ports to open:${RESET}"
|
||||
for p in "${FW_TCP[@]}"; do echo " ${p}/tcp"; done
|
||||
for p in "${FW_UDP[@]}"; do echo " ${p}/udp"; done
|
||||
echo ""
|
||||
|
||||
if ! ask_yn "Apply these rules?" "y"; then
|
||||
info "Skipped."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# ── Apply rules ───────────────────────────────────────────────────────────────
|
||||
apply_firewall_rules() {
|
||||
local fw="$1"
|
||||
|
||||
case "$fw" in
|
||||
|
||||
firewalld)
|
||||
for p in "${FW_TCP[@]}"; do
|
||||
firewall-cmd --permanent --add-port="${p}/tcp" && \
|
||||
success " firewalld: opened ${p}/tcp" || \
|
||||
error " firewalld: failed to open ${p}/tcp"
|
||||
done
|
||||
for p in "${FW_UDP[@]}"; do
|
||||
firewall-cmd --permanent --add-port="${p}/udp" && \
|
||||
success " firewalld: opened ${p}/udp" || \
|
||||
error " firewalld: failed to open ${p}/udp"
|
||||
done
|
||||
firewall-cmd --reload && success " firewalld: reloaded" || error " firewalld: reload failed"
|
||||
;;
|
||||
|
||||
ufw)
|
||||
for p in "${FW_TCP[@]}"; do
|
||||
ufw allow "${p}/tcp" && \
|
||||
success " ufw: allowed ${p}/tcp" || \
|
||||
error " ufw: failed to allow ${p}/tcp"
|
||||
done
|
||||
for p in "${FW_UDP[@]}"; do
|
||||
ufw allow "${p}/udp" && \
|
||||
success " ufw: allowed ${p}/udp" || \
|
||||
error " ufw: failed to allow ${p}/udp"
|
||||
done
|
||||
;;
|
||||
|
||||
nftables)
|
||||
# Add rules to the first inet/ip filter input chain found, or create one
|
||||
_NFT_TABLE="filter"
|
||||
_NFT_CHAIN="input"
|
||||
# Check if table/chain exist
|
||||
if ! nft list chain inet "${_NFT_TABLE}" "${_NFT_CHAIN}" &>/dev/null; then
|
||||
nft add table inet "${_NFT_TABLE}"
|
||||
nft add chain inet "${_NFT_TABLE}" "${_NFT_CHAIN}" \
|
||||
'{ type filter hook input priority 0 ; policy accept ; }'
|
||||
info " nftables: created table inet ${_NFT_TABLE} chain ${_NFT_CHAIN}"
|
||||
fi
|
||||
for p in "${FW_TCP[@]}"; do
|
||||
nft add rule inet "${_NFT_TABLE}" "${_NFT_CHAIN}" tcp dport "${p}" accept && \
|
||||
success " nftables: accepted ${p}/tcp" || \
|
||||
error " nftables: failed ${p}/tcp"
|
||||
done
|
||||
for p in "${FW_UDP[@]}"; do
|
||||
nft add rule inet "${_NFT_TABLE}" "${_NFT_CHAIN}" udp dport "${p}" accept && \
|
||||
success " nftables: accepted ${p}/udp" || \
|
||||
error " nftables: failed ${p}/udp"
|
||||
done
|
||||
# Persist
|
||||
if command -v nft &>/dev/null; then
|
||||
if [[ -d /etc/nftables.d ]]; then
|
||||
nft list ruleset > /etc/nftables.d/netbird-relay.nft && \
|
||||
success " nftables: saved to /etc/nftables.d/netbird-relay.nft"
|
||||
elif [[ -f /etc/nftables.conf ]]; then
|
||||
nft list ruleset > /etc/nftables.conf && \
|
||||
success " nftables: saved to /etc/nftables.conf"
|
||||
else
|
||||
warn " nftables: rules applied but not persisted — save manually with:"
|
||||
warn " nft list ruleset > /etc/nftables.conf"
|
||||
fi
|
||||
fi
|
||||
;;
|
||||
|
||||
iptables)
|
||||
for p in "${FW_TCP[@]}"; do
|
||||
iptables -C INPUT -p tcp --dport "${p}" -j ACCEPT 2>/dev/null || {
|
||||
iptables -A INPUT -p tcp --dport "${p}" -j ACCEPT && \
|
||||
success " iptables: opened ${p}/tcp" || \
|
||||
error " iptables: failed to open ${p}/tcp"
|
||||
}
|
||||
done
|
||||
for p in "${FW_UDP[@]}"; do
|
||||
iptables -C INPUT -p udp --dport "${p}" -j ACCEPT 2>/dev/null || {
|
||||
iptables -A INPUT -p udp --dport "${p}" -j ACCEPT && \
|
||||
success " iptables: opened ${p}/udp" || \
|
||||
error " iptables: failed to open ${p}/udp"
|
||||
}
|
||||
done
|
||||
# Persist
|
||||
if command -v netfilter-persistent &>/dev/null; then
|
||||
netfilter-persistent save && success " iptables: rules persisted via netfilter-persistent"
|
||||
elif command -v iptables-save &>/dev/null; then
|
||||
if [[ -f /etc/iptables/rules.v4 ]]; then
|
||||
iptables-save > /etc/iptables/rules.v4 && \
|
||||
success " iptables: saved to /etc/iptables/rules.v4"
|
||||
else
|
||||
warn " iptables: rules applied but not persisted — save manually with:"
|
||||
warn " iptables-save > /etc/iptables/rules.v4"
|
||||
fi
|
||||
fi
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
if [[ "$EUID" -ne 0 ]]; then
|
||||
warn "Not running as root — firewall commands may fail."
|
||||
warn "Re-run with sudo if needed."
|
||||
fi
|
||||
|
||||
apply_firewall_rules "$FW"
|
||||
echo ""
|
||||
success "Firewall rules applied. 🎉"
|
||||
Reference in New Issue
Block a user