Reset iptables ACCEPT rule for updates proxy if service is running

This commit is contained in:
unman 2017-02-11 02:11:53 +00:00
parent 7787d39b6e
commit 59b025a652
No known key found for this signature in database
GPG Key ID: FDD1B8244731B36C

View File

@ -51,6 +51,10 @@ while true; do
DISPLAY=:0 /usr/bin/notify-send -t 3000 "Firewall loading error ($(hostname))" "$OUT" || :
fi
if [ `systemctl is-active qubes-updates-proxy` = "active" ]; then
iptables -I INPUT -i vif+ -p tcp --dport 8082 -j ACCEPT
fi
# Check if user didn't define some custom rules to be applied as well...
[ -x /rw/config/qubes-firewall-user-script ] && /rw/config/qubes-firewall-user-script
# XXX: Backward compatibility