Additional changes: - Allow empty value for PIA region - Most settings are lowercased - `OPENVPN_VERBOSITY` environment variable - openvpn also tunnels IPv6, and unbound supports ipv6 - auth kept only on disk, not in memory - readme reworked - CI script fixed and improved - Added v2 Docker tag - Shadowsocks log defaults to `off`
43 lines
1.3 KiB
Go
43 lines
1.3 KiB
Go
package firewall
|
|
|
|
import (
|
|
"net"
|
|
|
|
"github.com/qdm12/golibs/command"
|
|
"github.com/qdm12/golibs/files"
|
|
"github.com/qdm12/golibs/logging"
|
|
"github.com/qdm12/private-internet-access-docker/internal/models"
|
|
)
|
|
|
|
const logPrefix = "firewall configurator"
|
|
|
|
// Configurator allows to change firewall rules and modify network routes
|
|
type Configurator interface {
|
|
Version() (string, error)
|
|
AcceptAll() error
|
|
Clear() error
|
|
BlockAll() error
|
|
CreateGeneralRules() error
|
|
CreateVPNRules(dev models.VPNDevice, defaultInterface string, connections []models.OpenVPNConnection) error
|
|
CreateLocalSubnetsRules(subnet net.IPNet, extraSubnets []net.IPNet, defaultInterface string) error
|
|
AddRoutesVia(subnets []net.IPNet, defaultGateway net.IP, defaultInterface string) error
|
|
GetDefaultRoute() (defaultInterface string, defaultGateway net.IP, defaultSubnet net.IPNet, err error)
|
|
AllowInputTrafficOnPort(device models.VPNDevice, port uint16) error
|
|
AllowAnyIncomingOnPort(port uint16) error
|
|
}
|
|
|
|
type configurator struct {
|
|
commander command.Commander
|
|
logger logging.Logger
|
|
fileManager files.FileManager
|
|
}
|
|
|
|
// NewConfigurator creates a new Configurator instance
|
|
func NewConfigurator(logger logging.Logger, fileManager files.FileManager) Configurator {
|
|
return &configurator{
|
|
commander: command.NewCommander(),
|
|
logger: logger,
|
|
fileManager: fileManager,
|
|
}
|
|
}
|