2002-05-01 01:13:15 +02:00
|
|
|
#
|
2006-10-05 02:04:59 +02:00
|
|
|
# Shorewall version 3.3 - Zones File
|
2002-05-01 01:13:15 +02:00
|
|
|
#
|
2005-08-02 18:46:30 +02:00
|
|
|
# /etc/shorewall/zones
|
|
|
|
#
|
2006-04-12 00:20:09 +02:00
|
|
|
# This file declares your network zones. You specify the hosts in
|
|
|
|
# each zone through entries in /etc/shorewall/interfaces or
|
|
|
|
# /etc/shorewall/hosts.
|
2005-08-02 18:46:30 +02:00
|
|
|
#
|
2005-12-11 17:13:15 +01:00
|
|
|
# WARNING: The format of this file changed in Shorewall 3.0.0. You can
|
|
|
|
# continue to use your old records provided that you set
|
|
|
|
# IPSECFILE=ipsec in /etc/shorewall/shorewall.conf. This will
|
|
|
|
# signal Shorewall that the IPSEC-related zone options are
|
|
|
|
# still specified in /etc/shorewall/ipsec rather than in this
|
|
|
|
# file.
|
|
|
|
#
|
|
|
|
# To use records in the format described below, you must have
|
2006-04-12 00:20:09 +02:00
|
|
|
# IPSECFILE=zones specified in /etc/shorewall/shorewall.conf
|
|
|
|
# AND YOU MUST NOT SET THE 'FW' VARIABLE IN THAT FILE!!!!!
|
2005-12-11 17:13:15 +01:00
|
|
|
#
|
2005-08-02 18:46:30 +02:00
|
|
|
# Columns are:
|
2002-05-01 01:13:15 +02:00
|
|
|
#
|
2006-10-05 00:48:54 +02:00
|
|
|
# ZONE Short name of the zone. The names "all" and "none" are reserved
|
|
|
|
# and may not be used as zone names. The maximum length of a
|
|
|
|
# zone name is determined by the setting of the LOGFORMAT option
|
|
|
|
# in shorewall.conf. With the default LOGFORMAT, zone names can
|
|
|
|
# be at most 5 characters long.
|
2005-07-26 01:08:09 +02:00
|
|
|
#
|
2005-09-09 00:30:32 +02:00
|
|
|
# Where a zone is nested in one or more other zones,
|
|
|
|
# you may follow the (sub)zone name by ":" and a
|
|
|
|
# comma-separated list of the parent zones. The parent
|
|
|
|
# zones must have been defined in earlier records in this
|
|
|
|
# file.
|
|
|
|
#
|
|
|
|
# Example:
|
|
|
|
#
|
|
|
|
# #ZONE TYPE OPTIONS
|
2005-09-30 19:16:22 +02:00
|
|
|
# a ipv4
|
|
|
|
# b ipv4
|
|
|
|
# c:a,b ipv4
|
2005-09-09 00:30:32 +02:00
|
|
|
#
|
2006-03-24 01:05:09 +01:00
|
|
|
# Currently, Shorewall uses this information to reorder the
|
2005-09-09 00:30:32 +02:00
|
|
|
# zone list so that parent zones appear after their subzones in
|
2006-03-24 01:05:09 +01:00
|
|
|
# the list. The IMPLICIT_CONTINUE option in shorewall.conf can
|
|
|
|
# also create implicit CONTINUE policies to/from the subzone.
|
|
|
|
#
|
|
|
|
# In the future, Shorewall may make additional use
|
|
|
|
# of nesting information.
|
2005-09-09 00:30:32 +02:00
|
|
|
#
|
2005-09-30 19:16:22 +02:00
|
|
|
# TYPE ipv4 - This is the standard Shorewall zone type and is the
|
2005-09-12 19:21:14 +02:00
|
|
|
# default if you leave this column empty or if you enter
|
|
|
|
# "-" in the column. Communication with some zone hosts
|
|
|
|
# may be encrypted. Encrypted hosts are designated using
|
|
|
|
# the 'ipsec'option in /etc/shorewall/hosts.
|
|
|
|
# ipsec - Communication with all zone hosts is encrypted
|
2005-09-02 22:46:53 +02:00
|
|
|
# Your kernel and iptables must include policy
|
2005-07-26 01:08:09 +02:00
|
|
|
# match support.
|
2005-09-02 22:46:53 +02:00
|
|
|
# firewall
|
2005-09-21 18:51:52 +02:00
|
|
|
# - Designates the firewall itself. You must have
|
2005-09-02 22:46:53 +02:00
|
|
|
# exactly one 'firewall' zone. No options are
|
2005-09-21 18:51:52 +02:00
|
|
|
# permitted with a 'firewall' zone. The name that you
|
2005-09-12 19:29:46 +02:00
|
|
|
# enter in the ZONE column will be stored in the shell
|
|
|
|
# variable $FW which you may use in other configuration
|
|
|
|
# files to designate the firewall zone.
|
2005-07-26 01:08:09 +02:00
|
|
|
#
|
2005-08-02 18:46:30 +02:00
|
|
|
# OPTIONS, A comma-separated list of options as follows:
|
2005-07-26 01:08:09 +02:00
|
|
|
# IN OPTIONS,
|
|
|
|
# OUT OPTIONS reqid=<number> where <number> is specified
|
|
|
|
# using setkey(8) using the 'unique:<number>
|
|
|
|
# option for the SPD level.
|
|
|
|
#
|
|
|
|
# spi=<number> where <number> is the SPI of
|
|
|
|
# the SA used to encrypt/decrypt packets.
|
|
|
|
#
|
|
|
|
# proto=ah|esp|ipcomp
|
|
|
|
#
|
2005-08-02 18:46:30 +02:00
|
|
|
# mss=<number> (sets the MSS field in TCP packets)
|
2005-07-26 01:08:09 +02:00
|
|
|
#
|
|
|
|
# mode=transport|tunnel
|
|
|
|
#
|
|
|
|
# tunnel-src=<address>[/<mask>] (only
|
|
|
|
# available with mode=tunnel)
|
|
|
|
#
|
|
|
|
# tunnel-dst=<address>[/<mask>] (only
|
|
|
|
# available with mode=tunnel)
|
|
|
|
#
|
2005-08-02 18:46:30 +02:00
|
|
|
# strict Means that packets must match all rules.
|
2005-07-26 01:08:09 +02:00
|
|
|
#
|
2005-08-02 18:46:30 +02:00
|
|
|
# next Separates rules; can only be used with
|
2006-03-24 01:05:09 +01:00
|
|
|
# strict
|
2005-07-26 01:08:09 +02:00
|
|
|
#
|
|
|
|
# Example:
|
|
|
|
# mode=transport,reqid=44
|
|
|
|
#
|
|
|
|
# The options in the OPTIONS column are applied to both incoming
|
|
|
|
# and outgoing traffic. The IN OPTIONS are applied to incoming
|
2005-08-02 18:46:30 +02:00
|
|
|
# traffic (in addition to OPTIONS) and the OUT OPTIONS are
|
2005-07-26 01:08:09 +02:00
|
|
|
# applied to outgoing traffic.
|
|
|
|
#
|
|
|
|
# If you wish to leave a column empty but need to make an entry
|
|
|
|
# in a following column, use "-".
|
2005-08-02 18:46:30 +02:00
|
|
|
#------------------------------------------------------------------------------
|
2005-07-09 07:45:05 +02:00
|
|
|
# Example zones:
|
2003-07-26 18:44:38 +02:00
|
|
|
#
|
2005-08-02 18:46:30 +02:00
|
|
|
# You have a three interface firewall with internet, local and DMZ
|
|
|
|
# interfaces.
|
2005-07-09 07:45:05 +02:00
|
|
|
#
|
2005-09-02 22:46:53 +02:00
|
|
|
# #ZONE TYPE OPTIONS IN OUT
|
|
|
|
# # OPTIONS OPTIONS
|
2005-09-21 18:51:52 +02:00
|
|
|
# fw firewall
|
2005-12-11 17:13:15 +01:00
|
|
|
# net ipv4
|
|
|
|
# loc ipv4
|
|
|
|
# dmz ipv4
|
2005-07-09 07:45:05 +02:00
|
|
|
#
|
2005-09-21 18:51:52 +02:00
|
|
|
#
|
|
|
|
# For more information, see http://www.shorewall.net/Documentation.htm#Zones
|
|
|
|
#
|
2005-08-02 18:46:30 +02:00
|
|
|
###############################################################################
|
2005-09-02 22:46:53 +02:00
|
|
|
#ZONE TYPE OPTIONS IN OUT
|
|
|
|
# OPTIONS OPTIONS
|
|
|
|
fw firewall
|
2002-05-01 01:13:15 +02:00
|
|
|
#LAST LINE - ADD YOUR ENTRIES ABOVE THIS ONE - DO NOT REMOVE
|