mirror of
https://gitlab.com/shorewall/code.git
synced 2024-12-28 09:08:48 +01:00
119 lines
2.5 KiB
Plaintext
119 lines
2.5 KiB
Plaintext
|
#
|
||
|
# Shorewall version 3.2 - xtables Modules File
|
||
|
#
|
||
|
# /etc/shorewall/xmodules
|
||
|
#
|
||
|
# This file loads the modules needed by the firewall on 2.6.16 and later
|
||
|
# kernels.
|
||
|
#
|
||
|
# THE ORDER OF THE COMMANDS BELOW IS IMPORTANT!!!!!! You MUST load in
|
||
|
# dependency order. i.e., if M2 depends on M1 then you must load M1
|
||
|
# before you load M2.
|
||
|
#
|
||
|
# For additional information, see
|
||
|
# http://shorewall.net/Documentation.htm#modules
|
||
|
#
|
||
|
###############################################################################
|
||
|
#
|
||
|
# Essential Modules
|
||
|
#
|
||
|
loadmodule nfnetlink
|
||
|
loadmodule x_tables
|
||
|
loadmodule ip_tables
|
||
|
loadmodule iptable_filter
|
||
|
loadmodule iptable_mangle
|
||
|
loadmodule ip_conntrack
|
||
|
loadmodule iptable_nat
|
||
|
loadmodule xt_state
|
||
|
loadmodule xt_tcpudp
|
||
|
#
|
||
|
# Other xtables modules
|
||
|
#
|
||
|
loadmodule xt_CLASSIFY
|
||
|
loadmodule xt_connmark
|
||
|
loadmodule xt_CONNMARK
|
||
|
loadmodule xt_conntrack
|
||
|
loadmodule xt_dccp
|
||
|
loadmodule xt_helper
|
||
|
loadmodule xt_length
|
||
|
loadmodule xt_limit
|
||
|
loadmodule xt_mac
|
||
|
loadmodule xt_mark
|
||
|
loadmodule xt_MARK
|
||
|
loadmodule xt_NFQUEUE
|
||
|
loadmodule xt_physdev
|
||
|
loadmodule xt_pkttype
|
||
|
loadmodule xt_tcpmss
|
||
|
#
|
||
|
# Helpers
|
||
|
#
|
||
|
loadmodule ip_conntrack_ftp
|
||
|
loadmodule ip_conntrack_tftp
|
||
|
loadmodule ip_conntrack_irc
|
||
|
loadmodule iptable_nat
|
||
|
loadmodule ip_nat_ftp
|
||
|
loadmodule ip_nat_tftp
|
||
|
loadmodule ip_nat_irc
|
||
|
loadmodule ip_set
|
||
|
loadmodule ip_set_iphash
|
||
|
loadmodule ip_set_ipmap
|
||
|
loadmodule ip_set_macipmap
|
||
|
loadmodule ip_set_portmap
|
||
|
#
|
||
|
# Traffic Shaping
|
||
|
#
|
||
|
loadmodule sch_sfq
|
||
|
loadmodule sch_ingress
|
||
|
loadmodule sch_htb
|
||
|
loadmodule cls_u32
|
||
|
#
|
||
|
# Extensions
|
||
|
#
|
||
|
loadmodule ipt_addrtype
|
||
|
loadmodule ipt_ah
|
||
|
loadmodule ipt_CLASSIFY
|
||
|
loadmodule ipt_CLUSTERIP
|
||
|
loadmodule ipt_comment
|
||
|
loadmodule ipt_connmark
|
||
|
loadmodule ipt_CONNMARK
|
||
|
loadmodule ipt_conntrack
|
||
|
loadmodule ipt_dscp
|
||
|
loadmodule ipt_DSCP
|
||
|
loadmodule ipt_ecn
|
||
|
loadmodule ipt_ECN
|
||
|
loadmodule ipt_esp
|
||
|
loadmodule ipt_hashlimit
|
||
|
loadmodule ipt_helper
|
||
|
loadmodule ipt_ipp2p
|
||
|
loadmodule ipt_iprange
|
||
|
loadmodule ipt_length
|
||
|
loadmodule ipt_limit
|
||
|
loadmodule ipt_LOG
|
||
|
loadmodule ipt_mac
|
||
|
loadmodule ipt_mark
|
||
|
loadmodule ipt_MARK
|
||
|
loadmodule ipt_MASQUERADE
|
||
|
loadmodule ipt_multiport
|
||
|
loadmodule ipt_NETMAP
|
||
|
loadmodule ipt_NOTRACK
|
||
|
loadmodule ipt_owner
|
||
|
loadmodule ipt_physdev
|
||
|
loadmodule ipt_pkttype
|
||
|
loadmodule ipt_policy
|
||
|
loadmodule ipt_realm
|
||
|
loadmodule ipt_recent
|
||
|
loadmodule ipt_REDIRECT
|
||
|
loadmodule ipt_REJECT
|
||
|
loadmodule ipt_SAME
|
||
|
loadmodule ipt_sctp
|
||
|
loadmodule ipt_set
|
||
|
loadmodule ipt_state
|
||
|
loadmodule ipt_tcpmss
|
||
|
loadmodule ipt_TCPMSS
|
||
|
loadmodule ipt_tos
|
||
|
loadmodule ipt_TOS
|
||
|
loadmodule ipt_ttl
|
||
|
loadmodule ipt_TTL
|
||
|
loadmodule ipt_ULOG
|
||
|
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|