don't reload firewall-cmd until all commands are added/deleted
This commit is contained in:
parent
5e22dcadf1
commit
03290d7a8d
1 changed files with 2 additions and 2 deletions
|
@ -14,7 +14,6 @@ add_NAT_forwarding() {
|
||||||
forward_to_port="$6"
|
forward_to_port="$6"
|
||||||
|
|
||||||
firewall-cmd --add-rich-rule "rule family=\"ipv4\" destination address=\"$original_destination_ip\" forward-port port=\"$original_destination_port\" protocol=\"$tcp_or_udp\" to-addr=\"$forward_to_ip\" to-port=\"$forward_to_port\"" --permanent > /dev/null
|
firewall-cmd --add-rich-rule "rule family=\"ipv4\" destination address=\"$original_destination_ip\" forward-port port=\"$original_destination_port\" protocol=\"$tcp_or_udp\" to-addr=\"$forward_to_ip\" to-port=\"$forward_to_port\"" --permanent > /dev/null
|
||||||
firewall-cmd --reload > /dev/null
|
|
||||||
|
|
||||||
echo "+ [$interface_source][$tcp_or_udp] $original_destination_ip:$original_destination_port --> $forward_to_ip:$forward_to_port"
|
echo "+ [$interface_source][$tcp_or_udp] $original_destination_ip:$original_destination_port --> $forward_to_ip:$forward_to_port"
|
||||||
}
|
}
|
||||||
|
@ -33,7 +32,6 @@ remove_NAT_forwarding() {
|
||||||
forward_to_port="$6"
|
forward_to_port="$6"
|
||||||
|
|
||||||
firewall-cmd --remove-rich-rule "rule family=\"ipv4\" destination address=\"$original_destination_ip\" forward-port port=\"$original_destination_port\" protocol=\"$tcp_or_udp\" to-addr=\"$forward_to_ip\" to-port=\"$forward_to_port\"" --permanent > /dev/null
|
firewall-cmd --remove-rich-rule "rule family=\"ipv4\" destination address=\"$original_destination_ip\" forward-port port=\"$original_destination_port\" protocol=\"$tcp_or_udp\" to-addr=\"$forward_to_ip\" to-port=\"$forward_to_port\"" --permanent > /dev/null
|
||||||
firewall-cmd --reload > /dev/null
|
|
||||||
|
|
||||||
echo "- [$interface_source][$tcp_or_udp] $original_destination_ip:$original_destination_port --> $forward_to_ip:$forward_to_port"
|
echo "- [$interface_source][$tcp_or_udp] $original_destination_ip:$original_destination_port --> $forward_to_ip:$forward_to_port"
|
||||||
}
|
}
|
||||||
|
@ -78,4 +76,6 @@ for rule in "${RULES[@]}"; do
|
||||||
esac
|
esac
|
||||||
done
|
done
|
||||||
|
|
||||||
|
firewall-cmd --reload > /dev/null
|
||||||
|
|
||||||
echo -e "\nDone! Don't forget to add/remove the rules in the security list."
|
echo -e "\nDone! Don't forget to add/remove the rules in the security list."
|
||||||
|
|
Loading…
Reference in a new issue