zhang888 1066 Posted ... Remove:iptables -A INPUT -s 10.0.0.0/8 -j DROP Air's infrastructure relies on this address space (DNS responses for example).Many people have their LANs on it too. The major section, let's just call it malformed packets, is imho redundant - the traffic never hitsyour network directly when you are connected to the VPN, it reaches Air's servers first wheresimilar rules already apply, in any case malformed packets will never reach you as first SYN.It will reach Air's server and stop there. Try to send random SYN with any flags to Air's serversand open tcpdump at your end, none of those packets will reach you.Same applies for most of these rules, like bruteforce protection. Traffic will never reach your ports,unless you forward them in the dashboard. And ports below <1024 you can't forward, so 443 makes no sense. Your script will have a better application on servers rather than on clients, imho. 1 cm0s reacted to this Quote Hide zhang888's signature Hide all signatures Occasional moderator, sometimes BOFH. Opinions are my own, except when my wife disagrees. Share this post Link to post