X-Git-Url: https://git.distorted.org.uk/~mdw/firewall/blobdiff_plain/89381fe13e3d664ba1d2bf407b0f49f2fd2040f4..a88692b74d2fcb561de02ac81fd595c6d0d0f75d:/telecaster.m4 diff --git a/telecaster.m4 b/telecaster.m4 index 4e3763d..dd278b8 100644 --- a/telecaster.m4 +++ b/telecaster.m4 @@ -32,8 +32,10 @@ allowservices inbound tcp \ ftp ftp_data \ rsync \ http https squid -allowservices inbound udp \ - icp + +run iptables -A inbound -j ACCEPT \ + -p udp --destination-port $port_icp \ + -m limit --limit 10/second --limit-burst 100 ## Other interesting things. dnsresolver inbound