From 68ce6b91d7625c808291dd48d20322547f7a6e76 Mon Sep 17 00:00:00 2001 From: ohrensessel Date: Wed, 27 Aug 2014 15:36:10 +0200 Subject: [PATCH] always filter ipv6 RH0 pakets --- files/etc/iptables/rules.v6 | 3 +++ 1 file changed, 3 insertions(+) diff --git a/files/etc/iptables/rules.v6 b/files/etc/iptables/rules.v6 index 4ee0a77..a00c3d0 100644 --- a/files/etc/iptables/rules.v6 +++ b/files/etc/iptables/rules.v6 @@ -13,5 +13,8 @@ COMMIT :INPUT ACCEPT [1244932:115240832] :FORWARD ACCEPT [51046:3997994] :OUTPUT ACCEPT [1330577:118074893] +-A INPUT -m rt --rt-type 0 -j DROP +-A FORWARD -m rt --rt-type 0 -j DROP +-A OUTPUT -m rt --rt-type 0 -j DROP COMMIT # Completed on Mon Aug 18 22:31:43 2014