Update iptables.sh

Adding IPtables DSCP QoS tagging - Thanks Brian K West for this suggestion.
This commit is contained in:
FusionPBX 2017-03-23 14:51:08 -06:00 committed by GitHub
parent ddca9feea4
commit 59c4f4473e
1 changed files with 3 additions and 0 deletions

View File

@ -34,6 +34,9 @@ iptables -A INPUT -p udp --dport 5080:5081 -j ACCEPT
iptables -A INPUT -p udp --dport 16384:32768 -j ACCEPT
iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT
iptables -A INPUT -p udp --dport 1194 -j ACCEPT
iptables -t mangle -A OUTPUT -p udp -m udp --sport 16384:32768 -j DSCP --set-dscp 46
iptables -t mangle -A OUTPUT -p udp -m udp --sport 5060:5081 -j DSCP --set-dscp 26
iptables -t mangle -A OUTPUT -p tcp -m tcp --sport 5060:5081 -j DSCP --set-dscp 26
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -P OUTPUT ACCEPT