28 lines
1.3 KiB
Bash
28 lines
1.3 KiB
Bash
#!/bin/sh
|
|
# Add Pleiades proxy port-forwards (CT777 .178): SOCKS5 :1080 + HTTP :8080.
|
|
# Appends to the JFFS firewall-start hook (reboot-persistent) + applies now.
|
|
|
|
cp /jffs/scripts/firewall-start /jffs/scripts/firewall-start.bak-pleiades-$(date +%s)
|
|
|
|
cat >> /jffs/scripts/firewall-start << 'EOF'
|
|
# Pleiades proxy store (CT777 .178): SOCKS5 :1080 + HTTP :8080 inbound
|
|
iptables -t nat -D VSERVER -p tcp --dport 1080 -j DNAT --to-destination 10.30.20.178:1080 2>/dev/null
|
|
iptables -t nat -A VSERVER -p tcp --dport 1080 -j DNAT --to-destination 10.30.20.178:1080
|
|
iptables -I FORWARD 1 -p tcp -d 10.30.20.178 --dport 1080 -j ACCEPT
|
|
iptables -t nat -D VSERVER -p tcp --dport 8080 -j DNAT --to-destination 10.30.20.178:8080 2>/dev/null
|
|
iptables -t nat -A VSERVER -p tcp --dport 8080 -j DNAT --to-destination 10.30.20.178:8080
|
|
iptables -I FORWARD 1 -p tcp -d 10.30.20.178 --dport 8080 -j ACCEPT
|
|
EOF
|
|
|
|
# apply immediately
|
|
for P in "1080:1080" "8080:8080"; do
|
|
EXT=${P%%:*}; DPT=${P##*:}
|
|
iptables -t nat -A VSERVER -p tcp --dport $EXT -j DNAT --to-destination 10.30.20.178:$DPT
|
|
iptables -I FORWARD 1 -p tcp -d 10.30.20.178 --dport $DPT -j ACCEPT
|
|
done
|
|
|
|
echo "=== VSERVER (pleiades) ==="
|
|
iptables -t nat -S VSERVER | grep -E "dport 1080|dport 8080"
|
|
echo "=== FORWARD (pleiades) ==="
|
|
iptables -S FORWARD | grep "10.30.20.178"
|