From c04bfdd1e60a5529824c7b7658fc13a3081bd6b8 Mon Sep 17 00:00:00 2001 From: Sun Knudsen Date: Wed, 6 Sep 2023 19:30:02 -0400 Subject: [PATCH] Updated rules --- how-to-self-host-hardened-jitsi-server/README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/how-to-self-host-hardened-jitsi-server/README.md b/how-to-self-host-hardened-jitsi-server/README.md index ea17e49..24269c5 100644 --- a/how-to-self-host-hardened-jitsi-server/README.md +++ b/how-to-self-host-hardened-jitsi-server/README.md @@ -89,6 +89,7 @@ iptables -A INPUT -p tcp --dport 80 --syn -m connlimit --connlimit-above 50 -j D iptables -A INPUT -p tcp --dport 80 -m conntrack --ctstate NEW -m limit --limit 60/s --limit-burst 20 -j ACCEPT iptables -A INPUT -p tcp --dport 443 --syn -m connlimit --connlimit-above 50 -j DROP iptables -A INPUT -p tcp --dport 443 -m conntrack --ctstate NEW -m limit --limit 60/s --limit-burst 20 -j ACCEPT +iptables -A INPUT -p tcp --dport 5349 -m state --state NEW -j ACCEPT iptables -A INPUT -p udp --dport 10000 -m state --state NEW -j ACCEPT iptables-save > /etc/iptables/rules.v4 ``` @@ -100,6 +101,7 @@ ip6tables -A INPUT -p tcp --dport 80 --syn -m connlimit --connlimit-above 50 -j ip6tables -A INPUT -p tcp --dport 80 -m conntrack --ctstate NEW -m limit --limit 60/s --limit-burst 20 -j ACCEPT ip6tables -A INPUT -p tcp --dport 443 --syn -m connlimit --connlimit-above 50 -j DROP ip6tables -A INPUT -p tcp --dport 443 -m conntrack --ctstate NEW -m limit --limit 60/s --limit-burst 20 -j ACCEPT +ip6tables -A INPUT -p tcp --dport 5349 -m state --state NEW -j ACCEPT ip6tables -A INPUT -p udp --dport 10000 -m state --state NEW -j ACCEPT ip6tables-save > /etc/iptables/rules.v6 ```