diff --git a/box/scripts/box.iptables b/box/scripts/box.iptables index 98e7add..1871cd5 100755 --- a/box/scripts/box.iptables +++ b/box/scripts/box.iptables @@ -117,7 +117,7 @@ disable_ipv6() { sysctl -w net.ipv6.conf.default.disable_ipv6=1 sysctl -w net.ipv6.conf.wlan0.disable_ipv6=1 - ip -6 rule add unreachable pref "${pref}" + # ip -6 rule add unreachable pref "${pref}" } >> /dev/null 2>&1 ipv6_enable() { @@ -130,7 +130,7 @@ ipv6_enable() { sysctl -w net.ipv6.conf.default.disable_ipv6=0 sysctl -w net.ipv6.conf.wlan0.disable_ipv6=0 - ip -6 rule del unreachable pref "${pref}" + # ip -6 rule del unreachable pref "${pref}" $IP6V -A OUTPUT -p udp --destination-port 53 -j DROP } >> /dev/null 2>&1 @@ -659,6 +659,34 @@ if [[ "${network_mode}" == @(redirect|mixed|tproxy|enhance) ]]; then log Warning "Disabling IPv6." fi ;; + redirect) + log Info "Using Redirect: tcp + udp (direct)." + log Info "Creating iptables transparent proxy rules." + + iptables="$IPV" + if start_redirect; then + log Info "Creating iptables transparent proxy rules done." + else + log Error "Creating iptables transparent proxy rule failed." + stop_redirect >> /dev/null 2>&1 + fi + + if [ "${ipv6}" = "true" ]; then + log Debug "Using IPv6." + ipv6_enable + iptables="$IP6V" + + if start_redirect; then + log Info "Creating ip6tables transparent proxy rules done." + else + log Error "Creating ip6tables transparent proxy rule failed." + stop_redirect >> /dev/null 2>&1 + fi + else + disable_ipv6 + log Warning "Disabling IPv6." + fi + ;; mixed) log Info "Using Mixed: tcp(redirect) + udp(tun)." log Info "Creating iptables transparent proxy rules." @@ -792,4 +820,4 @@ else echo "${yellow}Usage:${normal} ${green}$0${normal} {${yellow}enable|disable|renew${normal}}" ;; esac -fi +fi \ No newline at end of file