2012-06-12 - [GRASE-Hotspot] Block and open Ports

Header Data

From: Se***e@aol.com
Message Hash: 2cd4d9a6f83da82f5c2c2099c7e895e3e33e8c2237b7dbabbb93d370a4cc662e
Message ID: <13fa.4010002.3d08b26d@aol.com>
Reply To: N/A
UTC Datetime: 2012-06-12 07:55:41 UTC
Raw Date: Tue, 12 Jun 2012 10:55:41 -0400

Raw message

Hello,
 
the installation of Grase Hotspot was easy and it works really good right  
from the beginning. An impressive solution for hotspots, many thanks for  
that.
 
Before I want to implement Grase into our holiday appartements, I wanted to 
 know if I could only allow certain ports for user who are logged in. I've 
read  some topics about that. One said, that I should change the chilli 
ipup.sh  (bottom) "ipt -I POSTROUTING -t nat -o $HS_WANIF -j MASQUERADE" to "ipt 
-I  POSTROUTING -t nat -o $HS_WANIF --dport 443 -j MASQUERADE" and the 
ports I want  to open (excluding 80 and 53).
But this results in an opened port 80, and all those i wrote into ipup.sh  
are closed, even 443.
 
Could somebody tell me also the difference betweeen HS_TCP_Ports in the  
etc/chilli/config and ipup.sh masquerade?
 
Best regards
-Schneereich

Thread