A Linux netfilter module to aid in (d)dos protection
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
|
|
|
#!/bin/bash
|
|
|
|
|
|
|
|
if [ "$1" == "4" ]
|
|
|
|
then
|
|
|
|
IPTABLES=iptables
|
|
|
|
elif [ "$1" == "6" ]
|
|
|
|
then
|
|
|
|
IPTABLES=ip6tables
|
|
|
|
else
|
|
|
|
echo "specify either 4 or 6 as a parameter for ipv4 or ipv6";
|
|
|
|
exit -1
|
|
|
|
fi
|
|
|
|
|
|
|
|
#clear up ${IPTABLES}
|
|
|
|
sudo ${IPTABLES} -t raw -D PREROUTING -p udp --dport 9987 -j CT --notrack
|
|
|
|
sudo ${IPTABLES} -D INPUT -p udp --dport 9987 \! -f -j TS3_UDP_TRAFFIC
|
|
|
|
sudo ${IPTABLES} -D INPUT -p tcp --dport 30033 -j TS3_TCP_TRAFFIC
|
|
|
|
|
|
|
|
sudo ${IPTABLES} -F TS3_UDP_TRAFFIC
|
|
|
|
sudo ${IPTABLES} -F TS3_TCP_TRAFFIC
|
|
|
|
sudo ${IPTABLES} -F TS3_ACCEPT_NEW
|
|
|
|
sudo ${IPTABLES} -F TS3_UPDATE_AUTHORIZED
|
|
|
|
|
|
|
|
sudo ${IPTABLES} -X TS3_UDP_TRAFFIC
|
|
|
|
sudo ${IPTABLES} -X TS3_TCP_TRAFFIC
|
|
|
|
sudo ${IPTABLES} -X TS3_ACCEPT_NEW
|
|
|
|
sudo ${IPTABLES} -X TS3_UPDATE_AUTHORIZED
|
|
|
|
|
|
|
|
#delete the ipset
|
|
|
|
sudo ipset destroy ts3_authorized${1}
|