mirror of https://github.com/bol-van/zapret/
2 changed files with 31 additions and 1 deletions
@ -0,0 +1,30 @@ |
|||||
|
# this custom script runs desync to all stun packets |
||||
|
|
||||
|
# can override in config : |
||||
|
NFQWS_OPT_DESYNC_STUN="${NFQWS_OPT_DESYNC_STUN:---dpi-desync=fake}" |
||||
|
|
||||
|
alloc_dnum DNUM_STUN4ALL |
||||
|
alloc_qnum QNUM_STUN4ALL |
||||
|
|
||||
|
zapret_custom_daemons() |
||||
|
{ |
||||
|
# $1 - 1 - add, 0 - stop |
||||
|
|
||||
|
local opt="--qnum=$QNUM_STUN4ALL $NFQWS_OPT_DESYNC_STUN" |
||||
|
do_nfqws $1 $DNUM_STUN4ALL "$opt" |
||||
|
} |
||||
|
# size = 156 (8 udp header + 148 payload) && payload starts with 0x01000000 |
||||
|
zapret_custom_firewall() |
||||
|
{ |
||||
|
# $1 - 1 - run, 0 - stop |
||||
|
|
||||
|
local f='-p udp -p udp -m length --length 28: -m u32 --u32' |
||||
|
fw_nfqws_post $1 "$f 0>>22&0x3C@8&0xC0000003=0 && 0>>22&0x3C@12=0x2112A442" "$f 48&0xC0000003=0 && 52=0x2112A442" $QNUM_STUN4ALL |
||||
|
} |
||||
|
zapret_custom_firewall_nft() |
||||
|
{ |
||||
|
# stop logic is not required |
||||
|
|
||||
|
local f="udp length >= 28 @ih,0,2 0 @ih,30,2 0 @ih,32,32 0x2112A442" |
||||
|
nft_fw_nfqws_post "$f" "$f" $QNUM_STUN4ALL |
||||
|
} |
Loading…
Reference in new issue