#!/bin/sh
iptables -F
# Uncomment if there's a local network
# MYLOCALNETWORK="192.168.0.0/24"
# iptables -A OUTPUT -d $MYLOCALNETWORK -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT
# IPSEC
iptables -A OUTPUT -m policy --dir out --pol ipsec -j ACCEPT
iptables -A OUTPUT -p udp --dport 4500 -j ACCEPT
iptables -A OUTPUT -p udp --dport 500 -j ACCEPT
iptables -A OUTPUT -p ah -j ACCEPT
iptables -A OUTPUT -p esp -j ACCEPT
# DNS
iptables -A OUTPUT -p udp --dport 53 -j ACCEPT
# DROP ALL
iptables -A OUTPUT -j DROP