|
@@ -4,10 +4,6 @@ luser=anon
|
|
nofw=nofw
|
|
nofw=nofw
|
|
cable=cable
|
|
cable=cable
|
|
|
|
|
|
-# Assumes the actual IP is in /etc/hosts (cf. /etc/conf.d/tlsdated)
|
|
|
|
-tlsdate=tlsdate
|
|
|
|
-tlsdateip=www.google.com
|
|
|
|
-
|
|
|
|
# ReachableAddresses ports in /etc/tor/torrc [uid=tor]
|
|
# ReachableAddresses ports in /etc/tor/torrc [uid=tor]
|
|
# (allow high ports in order to support most bridges)
|
|
# (allow high ports in order to support most bridges)
|
|
torports=80,443,1024:65535
|
|
torports=80,443,1024:65535
|
|
@@ -133,9 +129,6 @@ if [ ${luser} = ${nofw} ]; then
|
|
iptables -A OUTPUT -p tcp -m owner --uid-owner privoxy --syn --dport domain -j ACCEPT
|
|
iptables -A OUTPUT -p tcp -m owner --uid-owner privoxy --syn --dport domain -j ACCEPT
|
|
fi
|
|
fi
|
|
|
|
|
|
-# Time synchronization via tlsdate
|
|
|
|
-iptables -A OUTPUT -p tcp -m owner --uid-owner ${tlsdate} --syn -d ${tlsdateip} --dport https -j ACCEPT
|
|
|
|
-
|
|
|
|
# VPN connections (root-initiated)
|
|
# VPN connections (root-initiated)
|
|
iptables -A OUTPUT -p tcp -m owner --uid-owner root --syn -m multiport --dports ${vpntports} -j ACCEPT
|
|
iptables -A OUTPUT -p tcp -m owner --uid-owner root --syn -m multiport --dports ${vpntports} -j ACCEPT
|
|
iptables -A OUTPUT -p udp -m owner --uid-owner root -m multiport --dports ${vpnuports} -j ACCEPT
|
|
iptables -A OUTPUT -p udp -m owner --uid-owner root -m multiport --dports ${vpnuports} -j ACCEPT
|