From 84b45f3559c40fc3ad4a287d56a8ee013fc8ef39 Mon Sep 17 00:00:00 2001 From: Stefan Huber Date: Fri, 8 Oct 2021 17:00:17 +0200 Subject: [PATCH] letsencrypt: Kill iptables interface restriction --- letsencrypt/renewal.sh | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/letsencrypt/renewal.sh b/letsencrypt/renewal.sh index eb9c9df..b21d4c8 100644 --- a/letsencrypt/renewal.sh +++ b/letsencrypt/renewal.sh @@ -13,8 +13,8 @@ PORT80=$(lsof -ti :80 | wc -l) if [ $PORT80 = 0 ]; then cd /var/www/challenges nohup python3 -m http.server 80 > /dev/null 2>&1 & - /usr/sbin/iptables -A INPUT -i venet0 -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT - /usr/sbin/ip6tables -A INPUT -i venet0 -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT + /usr/sbin/iptables -A INPUT -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT + /usr/sbin/ip6tables -A INPUT -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT fi @@ -64,7 +64,7 @@ fi # Stop temp web server and close port 80 if needed. if [ $PORT80 = 0 ]; then - /usr/sbin/iptables -D INPUT -i venet0 -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT - /usr/sbin/ip6tables -D INPUT -i venet0 -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT + /usr/sbin/iptables -D INPUT -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT + /usr/sbin/ip6tables -D INPUT -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT pkill -f http.server fi -- 2.30.2