-
Notifications
You must be signed in to change notification settings - Fork 6
/
10-ipset
55 lines (47 loc) · 1.02 KB
/
10-ipset
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
#!/bin/bash
# This script is a plugin of netfilter-persistent.
# Please put it into /usr/share/netfilter-persistent/plugins.d
# NOTE: Ensure this file is executable.
set -e
rc=0
load_rules()
{
if [ ! -f /etc/iptables/rules.ipset ] || [ ! -f /etc/iptables/rules.ipset ]; then
echo "Warning: skipping IPSet (missing rules file)"
else
grep ^create /etc/iptables/rules.ipset | ipset restore 2>/dev/null || true
grep ^add /etc/iptables/rules.ipset | ipset restore 2>/dev/null
if [ $? -ne 0 ]; then
rc=1
fi
fi
}
save_rules()
{
ipset save > /etc/iptables/rules.ipset
}
flush_rules()
{
ipset flush
}
case "$1" in
start|restart|reload|force-reload)
flush_rules
load_rules
;;
save)
save_rules
;;
stop)
# destroy is not acceptable here because a set could be in use.
echo "stop (destroy) is not supported."
;;
flush)
flush_rules
;;
*)
echo "Usage: $0 {start|restart|reload|force-reload|save|flush}" >&2
exit 1
;;
esac
exit $rc