dockerd: set docker zone chain defaults to ACCEPT
authorGerard Ryan <G.M0N3Y.2503@gmail.com>
Sat, 20 Feb 2021 07:59:58 +0000 (17:59 +1000)
committerGerard Ryan <G.M0N3Y.2503@gmail.com>
Thu, 25 Feb 2021 11:33:39 +0000 (21:33 +1000)
* Since the docker0 is a private network by default we can be
  more accepting like the LAN is by default

Signed-off-by: Gerard Ryan <G.M0N3Y.2503@gmail.com>
utils/dockerd/files/dockerd.init

index 54268f1258fe1ec5b480561e1337853f29b50291..2eb272a70c5e563ef44bdc62976d819f3e0304ac 100755 (executable)
@@ -66,9 +66,9 @@ uciadd() {
                uci_quiet add firewall zone
                uci_quiet rename firewall.@zone[-1]="${zone}"
                uci_quiet set firewall.@zone[-1].network="${iface}"
-               uci_quiet set firewall.@zone[-1].input="REJECT"
+               uci_quiet set firewall.@zone[-1].input="ACCEPT"
                uci_quiet set firewall.@zone[-1].output="ACCEPT"
-               uci_quiet set firewall.@zone[-1].forward="REJECT"
+               uci_quiet set firewall.@zone[-1].forward="ACCEPT"
                uci_quiet set firewall.@zone[-1].name="${zone}"
                uci_quiet commit firewall
        fi