-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathsetup-firewalld.sh
More file actions
62 lines (52 loc) · 1.32 KB
/
setup-firewalld.sh
File metadata and controls
62 lines (52 loc) · 1.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
#!/bin/sh
DEFAULT_ZONE="$(firewall-cmd --get-default-zone)"
SERVICES=("kdeconnect" "spotify-sync")
SOURCES=("192.168.1.0/28")
set_default_zone_block()
{
if test "${DEFAULT_ZONE}" = "public"
then
sudo firewall-cmd --set-default-zone "block"
else
echo "[warn] The firewalld default zone is already set to: ${DEFAULT_ZONE}"
return 2
fi
return $?
}
add_services()
{
for service in ${SERVICES[@]}
do
if test ! "$(sudo firewall-cmd --list-service | grep -o ${service})" = "${service}"
then
sudo firewall-cmd --permanent --add-service "${service}"
if test $? -eq 0
then
echo "Reloading FirewallD..."
sudo firewall-cmd --complete-reload
fi
else
echo "${service}: service already enabled"
fi
done
return $?
}
add_sources()
{
for source in ${SOURCES[@]}
do
if test ! "$(sudo firewall-cmd --list-service | grep -o ${source})" = "${source}"
then
sudo firewall-cmd --permanent --add-sources "${source}"
else
echo "[error] ${source}: source already enabled"
fi
done
if test $? -ne 1
then
sudo firewall-cmd --complete-reload
fi
return $?
}
set_default_zone_block
add_services