X-Git-Url: https://iankelling.org/git/?p=automated-distro-installer;a=blobdiff_plain;f=wrt-setup;h=1c4a033c3f3c4cf9c92ab70bd1aa612920db6379;hp=86e82cfd128c78beb2cad792db041b3bb5f07ec0;hb=05e47f6734e5a9354a3243686ae55fe4ab2b72c7;hpb=efcfb463ceda4de1d9953da31a2c0737471e5cf8 diff --git a/wrt-setup b/wrt-setup index 86e82cf..1c4a033 100755 --- a/wrt-setup +++ b/wrt-setup @@ -18,7 +18,6 @@ set -eE -o pipefail trap 'echo "$0:$LINENO:error: \"$BASH_COMMAND\" returned $?" >&2' ERR -# ssh pmirror() { # background: upgrading all packages is not recommended because it @@ -92,28 +91,32 @@ mkdir -p /run/archiso/bootmnt # todo: at some later time, i found /mnt/usb not mounted, watch to see if # that is the case after running this or rebooting. # wiki says safe to do in case of fstab changes: -cedit /etc/config/fstab <<'EOF' || { v block umount; v block mount; } -config global automount - option from_fstab 1 - option anon_mount 1 - -config global autoswap - option from_fstab 1 - option anon_swap 1 - -config mount - option target /mnt/usb - option device /dev/sda2 - option fstype ext4 - option options rw,async,noatime,nodiratime - option enabled 1 - option enabled_fsck 0 - -config swap - option device /dev/sda1 - option enabled 1 -EOF +## ian: commented and replaced with just an echo +## since usb port seems to be busted. +echo | cedit /etc/config/fstab ||: +# cedit /etc/config/fstab <<'EOF' || { v block umount; v block mount; } +# config global automount +# option from_fstab 1 +# option anon_mount 1 + +# config global autoswap +# option from_fstab 1 +# option anon_swap 1 + +# config mount +# option target /mnt/usb +# option device /dev/sda2 +# option fstype ext2 +# option options rw,async,noatime,nodiratime +# option enabled 1 +# option enabled_fsck 0 + +# config swap +# option device /dev/sda1 +# option enabled 1 + +# EOF @@ -176,7 +179,7 @@ config 'route' 'transmission' option 'interface' 'lan' option 'target' '10.173.0.0' option 'netmask' '255.255.0.0' - option 'gateway' '192.168.1.2' + option 'gateway' '192.168.1.3' EOF v cedit /etc/config/firewall <<'EOF' || firewall_restart=true @@ -184,7 +187,7 @@ config redirect option name ssh option src wan option src_dport 22 - option dest_ip 192.168.1.2 + option dest_ip 192.168.1.8 option dest lan config rule option src wan @@ -207,7 +210,7 @@ config redirect option src wan option src_dport 443 option dest lan - option dest_ip 192.168.1.2 + option dest_ip 192.168.1.8 option proto tcp config rule option src wan @@ -217,110 +220,40 @@ config rule config redirect option src wan - option src_dport 80 + option src_dport 1196 option dest lan - option dest_ip 192.168.1.2 - option proto tcp + option dest_ip 192.168.1.8 + option proto udp config rule option src wan option target ACCEPT - option dest_port 80 - option proto tcp + option dest_port 1196 + option proto udp -config redirect - option name syncthing - option src wan - option src_dport 22001 - option dest_ip 192.168.1.2 - option dest lan -config rule - option src wan - option target ACCEPT - option dest_port 22001 -#### begin rules for nfs #### -# https://serverfault.com/questions/377170/which-ports-do-i-need-to-open-in-the-firewall-to-use-nfs -# https://wiki.debian.org/SecuringNFS -# I had no /etc/default/quota, or any process named quota anything, -# so, assumed that was unneeded. seems to work. -config redirect - option src wan - option src_dport 111 - option dest_ip 192.168.1.2 - option dest lan -config rule - option src wan - option target ACCEPT - option dest_port 111 -config redirect - option src wan - option src_dport 2049 - option dest_ip 192.168.1.2 - option dest lan -config rule - option src wan - option target ACCEPT - option dest_port 2049 config redirect option src wan - option src_dport 32764 - option dest_ip 192.168.1.2 - option dest lan -config rule - option src wan - option target ACCEPT - option dest_port 32764 -config redirect - option src wan - option src_dport 32765 - option dest_ip 192.168.1.2 - option dest lan -config rule - option src wan - option target ACCEPT - option dest_port 32765 -config redirect - option src wan - option src_dport 32766 - option dest_ip 192.168.1.2 - option dest lan -config rule - option src wan - option target ACCEPT - option dest_port 32766 -config redirect - option src wan - option src_dport 32767 - option dest_ip 192.168.1.2 - option dest lan -config rule - option src wan - option target ACCEPT - option dest_port 32767 -config redirect - option src wan - option src_dport 32768 - option dest_ip 192.168.1.2 + option src_dport 80 option dest lan + option dest_ip 192.168.1.8 + option proto tcp config rule option src wan option target ACCEPT - option dest_port 32768 -#### end rules for nfs #### - + option dest_port 80 + option proto tcp config redirect - option name mariadb + option name syncthing option src wan - option src_dport 3306 + option src_dport 22001 + option dest_ip 192.168.1.8 option dest lan - option dest_ip 192.168.1.2 - option proto tcp config rule option src wan option target ACCEPT - option dest_port 3306 - option proto tcp + option dest_port 22001 + EOF @@ -329,16 +262,21 @@ EOF dnsmasq_restart=false +mail_host=$(grep -F mail.iankelling.org /etc/hosts | awk '{print $1}') v cedit /etc/hosts <