use gateway ipv4 incomoing hook var instead of editing whonix_firewall

Information

ID: 176
PHID: PHID-TASK-ed7c4cko62aigoif5gj5
Author: Patrick
Status at Migration Time: resolved
Priority at Migration Time: Normal

Description

https://github.com/nrgaway/qubes-whonix/blob/master/usr/lib/qubes-whonix/init/qubes-whonix-firewall#L30

# Inject custom firewall rules into whonix_firewall

I would be happy if we could add some suitable hook mechanism to whonix_firewall or add some if/then code to whonix_firewall to simplify that code. Sed injection doesn’t look future proof. (Done.)

Create a file /etc/whonix_firewall.d/32_qubes with a content like this:

GATEWAY_IPv4_DROP_INVALID_INCOMING_PACKAGES_POST_HOOK=`/path/to/script`

Then you can add your injected rules there instead of using sed to edit /usr/bin/whonix_firewall.

Comments


Patrick

2015-02-15 18:01:17 UTC


Patrick

2015-02-15 18:06:57 UTC


nrgaway

2015-02-16 08:21:17 UTC


Patrick

2015-02-16 09:37:12 UTC


Patrick

2015-02-16 09:41:44 UTC


WhonixQubes

2015-02-16 10:03:23 UTC


Patrick

2015-02-16 10:05:47 UTC


nrgaway

2015-02-16 12:04:49 UTC


WhonixQubes

2015-02-16 12:39:44 UTC


Patrick

2015-02-16 13:28:20 UTC


WhonixQubes

2015-02-16 13:52:26 UTC


nrgaway

2015-02-16 15:54:25 UTC


Patrick

2015-02-16 21:01:08 UTC


nrgaway

2015-02-22 21:09:49 UTC


Patrick

2015-02-22 22:09:12 UTC


Patrick

2015-04-23 00:23:02 UTC


nrgaway

2015-04-30 07:11:03 UTC