From 042f511cbc02e14fe8229b493558ef828e413bea Mon Sep 17 00:00:00 2001 From: rtrimana Date: Thu, 21 Dec 2017 11:51:46 -0800 Subject: [PATCH 1/1] Removing forward rules on router for SSH traffic entirely after Sentinel bootstrap sequence --- iotjava/iotruntime/master/RouterConfig.java | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/iotjava/iotruntime/master/RouterConfig.java b/iotjava/iotruntime/master/RouterConfig.java index e6e0413..48bb8f6 100644 --- a/iotjava/iotruntime/master/RouterConfig.java +++ b/iotjava/iotruntime/master/RouterConfig.java @@ -648,8 +648,8 @@ public final class RouterConfig { strConfigHost + " -d " + strMonitorHost + " -p tcp --dport ssh"); pwConfig.println("-A OUTPUT -j ACCEPT -s " + strConfigHost + " -d " + strMonitorHost + " -p tcp --sport ssh"); - pwConfig.println("-A FORWARD -j ACCEPT -p tcp --dport ssh"); - pwConfig.println("-A FORWARD -j ACCEPT -p tcp --sport ssh"); + //pwConfig.println("-A FORWARD -j ACCEPT -p tcp --dport ssh"); + //pwConfig.println("-A FORWARD -j ACCEPT -p tcp --sport ssh"); } -- 2.34.1