- General improvements
- Parallel download of only needed files at start
- Prettier console output with all streams merged (openvpn, unbound, shadowsocks etc.)
- Simplified Docker final image
- Faster bootup
- DNS over TLS
- Finer grain blocking at DNS level: malicious, ads and surveillance
- Choose your DNS over TLS providers
- Ability to use multiple DNS over TLS providers for DNS split horizon
- Environment variables for DNS logging
- DNS block lists needed are downloaded and built automatically at start, in parallel
- PIA
- A random region is selected if the REGION parameter is left empty (thanks @rorph for your PR)
- Routing and iptables adjusted so it can work as a Kubernetes pod sidecar (thanks @rorph for your PR)
43 lines
1.3 KiB
Go
43 lines
1.3 KiB
Go
package firewall
|
|
|
|
import (
|
|
"net"
|
|
|
|
"github.com/qdm12/golibs/command"
|
|
"github.com/qdm12/golibs/files"
|
|
"github.com/qdm12/golibs/logging"
|
|
"github.com/qdm12/private-internet-access-docker/internal/models"
|
|
)
|
|
|
|
const logPrefix = "firewall configurator"
|
|
|
|
// Configurator allows to change firewall rules and modify network routes
|
|
type Configurator interface {
|
|
Version() (string, error)
|
|
AcceptAll() error
|
|
Clear() error
|
|
BlockAll() error
|
|
CreateGeneralRules() error
|
|
CreateVPNRules(dev models.VPNDevice, serverIPs []net.IP, defaultInterface string,
|
|
port uint16, protocol models.NetworkProtocol) error
|
|
CreateLocalSubnetsRules(subnet net.IPNet, extraSubnets []net.IPNet, defaultInterface string) error
|
|
AddRoutesVia(subnets []net.IPNet, defaultGateway net.IP, defaultInterface string) error
|
|
GetDefaultRoute() (defaultInterface string, defaultGateway net.IP, defaultSubnet net.IPNet, err error)
|
|
AllowInputTrafficOnPort(device models.VPNDevice, port uint16) error
|
|
}
|
|
|
|
type configurator struct {
|
|
commander command.Commander
|
|
logger logging.Logger
|
|
fileManager files.FileManager
|
|
}
|
|
|
|
// NewConfigurator creates a new Configurator instance
|
|
func NewConfigurator(logger logging.Logger, fileManager files.FileManager) Configurator {
|
|
return &configurator{
|
|
commander: command.NewCommander(),
|
|
logger: logger,
|
|
fileManager: fileManager,
|
|
}
|
|
}
|