diff --git a/OpenVPN-server:-Firewall-configuration-(using-iptables).md b/OpenVPN-server:-Firewall-configuration-(using-iptables).md index 8cc2ff9..d49b11e 100644 --- a/OpenVPN-server:-Firewall-configuration-(using-iptables).md +++ b/OpenVPN-server:-Firewall-configuration-(using-iptables).md @@ -74,13 +74,14 @@ If your server is reachable via IPv6, you'll need to run the same commands but u ip6tables -A INPUT -i tun0 -p tcp --destination-port 53 -j ACCEPT ip6tables -A INPUT -i tun0 -p udp --destination-port 53 -j ACCEPT ip6tables -A INPUT -i tun0 -p tcp --destination-port 80 -j ACCEPT -ip6tables -A INPUT -i tun0 -p udp --destination-port 80 -j ACCEPT ip6tables -A INPUT -p tcp --destination-port 22 -j ACCEPT ip6tables -A INPUT -p tcp --destination-port 1194 -j ACCEPT ip6tables -A INPUT -p udp --destination-port 1194 -j ACCEPT ip6tables -I INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT ip6tables -I INPUT -i lo -j ACCEPT -ip6tables -A INPUT -p tcp --dport 443 -j REJECT +ip6tables -A INPUT -p udp --dport 80 -j REJECT -- reject-with icmp-port-unreachable +ip6tables -A INPUT -p tcp --dport 443 -j REJECT --reject-with tcp-reset +ip6tables -A INPUT -p udp --dport 443 -j REJECT -- reject-with icmp-port-unreachable ip6tables -P INPUT DROP ``` View the rules you just created