From 92b55795021ee8967ac3f481707dcdab193feff0 Mon Sep 17 00:00:00 2001 From: quindecim <49964366+quindecim@users.noreply.github.com> Date: Sat, 30 Jul 2022 00:00:58 +0200 Subject: [PATCH] [config] Force disable ipv6 OS connections --- post-fs-data.sh | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/post-fs-data.sh b/post-fs-data.sh index f2ec45f..06b5f2e 100644 --- a/post-fs-data.sh +++ b/post-fs-data.sh @@ -8,7 +8,14 @@ MODDIR=${0%/*} # This script will be executed in post-fs-data mode +# Redirect DNS requests to localhost iptables -t nat -A OUTPUT -p tcp ! -d 91.239.100.100 --dport 53 -j DNAT --to-destination 127.0.0.1:5354 iptables -t nat -A OUTPUT -p udp ! -d 91.239.100.100 --dport 53 -j DNAT --to-destination 127.0.0.1:5354 # ip6tables -t nat -A OUTPUT -p tcp ! -d 91.239.100.100 --dport 53 -j DNAT --to-destination [::1]:5354 # ip6tables -t nat -A OUTPUT -p udp ! -d 91.239.100.100 --dport 53 -j DNAT --to-destination [::1]:5354 + +# Force disable IPv6 OS connections +resetprop net.ipv6.conf.all.accept_redirects 0 +resetprop net.ipv6.conf.all.disable_ipv6 1 +resetprop net.ipv6.conf.default.accept_redirects 0 +resetprop net.ipv6.conf.default.disable_ipv6 1