diff --git a/files/firewall b/files/firewall index 71059ce..22af592 100755 --- a/files/firewall +++ b/files/firewall @@ -31,6 +31,8 @@ case $1 in iptables -A INPUT -p icmp -j ACCEPT ## traffic we want to see encrypted over the VPN iptables -A INPUT -m policy --pol ipsec --dir in -p udp --dport 4789 -j ACCEPT # vxlan traffic + iptables -A INPUT -m policy --pol ipsec --dir in -p tcp --dport 8080 -j ACCEPT # ceph rgw traffic + iptables -A INPUT -m policy --pol ipsec --dir in -p tcp --sport 8080 -j ACCEPT # ceph rgw traffic iptables -A INPUT -m policy --pol ipsec --dir in -p tcp --dport 6789 -j ACCEPT # ceph mon traffic iptables -A INPUT -m policy --pol ipsec --dir in -p tcp --sport 6789 -j ACCEPT # ceph mon traffic iptables -A INPUT -m policy --pol ipsec --dir in -m multiport -p tcp --dports 6800:7300 -j ACCEPT # ceph traffic