Browse Source

Add killswitch

master
Matthew Faltys 7 years ago
parent
commit
0304f70c35
  1. 1
      Makefile
  2. 18
      deps/run.sh

1
Makefile

@ -21,6 +21,7 @@ run:
-d \
--name seedpod \
--cap-add=NET_ADMIN \
--cap-add=NET_RAW \
--device=/dev/net/tun \
--dns=8.8.8.8 \
-p 9091:9091 \

18
deps/run.sh vendored

@ -1,4 +1,18 @@
#!/bin/ash
openvpn /config.ovpn &
transmission-daemon --foreground --config-dir /transmission
# add killswitch rules
iptables -A INPUT -i tun+ -j ACCEPT
iptables -A OUTPUT -o tun+ -j ACCEPT
iptables -A INPUT -s 127.0.0.1 -j ACCEPT
iptables -A OUTPUT -d 127.0.0.1 -j ACCEPT
iptables -A INPUT -p tcp --dport 9091 -j ACCEPT
iptables -A OUTPUT -p tcp --sport 9091 -j ACCEPT
iptables -I OUTPUT 1 -m owner --uid-owner root -p udp --dport 53 -j ACCEPT
iptables -A OUTPUT -m mark ! --mark 0x1 ! -o tun+ -j DROP
# start openvpn with killswitch whitelist mark
openvpn --mark 1 --config /config.ovpn &
# start transmission
transmission-daemon --foreground --config-dir /transmission

Loading…
Cancel
Save