2009-02-16 19:39:01 +01:00
|
|
|
|
<?xml version="1.0" encoding="UTF-8"?>
|
|
|
|
|
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.4//EN"
|
|
|
|
|
"http://www.oasis-open.org/docbook/xml/4.4/docbookx.dtd">
|
|
|
|
|
<refentry>
|
|
|
|
|
<refmeta>
|
2012-08-02 20:02:17 +02:00
|
|
|
|
<refentrytitle>shorewall6-conntrack</refentrytitle>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
|
|
|
|
|
<manvolnum>5</manvolnum>
|
2014-01-16 17:32:57 +01:00
|
|
|
|
|
|
|
|
|
<refmiscinfo>Configuration Files</refmiscinfo>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
</refmeta>
|
|
|
|
|
|
|
|
|
|
<refnamediv>
|
2012-08-02 20:02:17 +02:00
|
|
|
|
<refname>conntrack</refname>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
|
2012-08-02 20:02:17 +02:00
|
|
|
|
<refpurpose>shorewall6 conntrack file</refpurpose>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
</refnamediv>
|
|
|
|
|
|
|
|
|
|
<refsynopsisdiv>
|
|
|
|
|
<cmdsynopsis>
|
2012-08-02 20:02:17 +02:00
|
|
|
|
<command>/etc/shorewall6/conntrack</command>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
</cmdsynopsis>
|
|
|
|
|
</refsynopsisdiv>
|
|
|
|
|
|
|
|
|
|
<refsect1>
|
|
|
|
|
<title>Description</title>
|
|
|
|
|
|
2012-08-02 20:02:17 +02:00
|
|
|
|
<para>The original intent of the <emphasis role="bold">notrack</emphasis>
|
|
|
|
|
file was to exempt certain traffic from Netfilter connection tracking.
|
2012-11-23 05:56:56 +01:00
|
|
|
|
Traffic matching entries in the file were not to be tracked.</para>
|
2011-12-05 15:56:23 +01:00
|
|
|
|
|
|
|
|
|
<para>The role of the file was expanded in Shorewall 4.4.27 to include all
|
2012-08-02 20:02:17 +02:00
|
|
|
|
rules that can be added in the Netfilter <emphasis
|
|
|
|
|
role="bold">raw</emphasis> table. In 4.5.7, the file's name was changed to
|
|
|
|
|
<emphasis role="bold">conntrack</emphasis>.</para>
|
2011-12-05 15:56:23 +01:00
|
|
|
|
|
2012-11-23 05:56:56 +01:00
|
|
|
|
<para>The file supports two different column layouts: FORMAT 1, FORMAT 2,
|
|
|
|
|
and FORMAT 3, FORMAT 1 being the default. The three differ as
|
|
|
|
|
follows:</para>
|
|
|
|
|
|
|
|
|
|
<itemizedlist>
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>in FORMAT 2 and 3, there is an additional leading ACTION
|
|
|
|
|
column.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>in FORMAT 3, the SOURCE column accepts no zone name; rather the
|
|
|
|
|
ACTION column allows a SUFFIX that determines the chain(s) that the
|
|
|
|
|
generated rule will be added to.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</itemizedlist>
|
|
|
|
|
|
|
|
|
|
<para>When an entry in the following form is encountered, the format of
|
|
|
|
|
the following entries are assumed to be of the specified
|
|
|
|
|
<replaceable>format</replaceable>.</para>
|
2011-12-05 15:56:23 +01:00
|
|
|
|
|
|
|
|
|
<simplelist>
|
2015-08-22 17:00:38 +02:00
|
|
|
|
<member><emphasis role="bold">?FORMAT</emphasis>
|
2012-11-23 05:56:56 +01:00
|
|
|
|
<replaceable>format</replaceable></member>
|
2011-12-05 15:56:23 +01:00
|
|
|
|
</simplelist>
|
|
|
|
|
|
|
|
|
|
<para>where <replaceable>format</replaceable> is either <emphasis
|
2012-11-23 05:56:56 +01:00
|
|
|
|
role="bold">1</emphasis>,<emphasis role="bold">2</emphasis> or <emphasis
|
|
|
|
|
role="bold">3</emphasis>.</para>
|
|
|
|
|
|
2015-08-22 17:00:38 +02:00
|
|
|
|
<para>Format 3 was introduced in Shorewall 4.5.10.</para>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
|
2012-08-03 19:53:20 +02:00
|
|
|
|
<para>Comments may be attached to Netfilter rules generated from entries
|
2015-08-22 17:00:38 +02:00
|
|
|
|
in this file through the use of ?COMMENT lines. These lines begin with
|
|
|
|
|
?COMMENT; the remainder of the line is treated as a comment which is
|
|
|
|
|
attached to subsequent rules until another ?COMMENT line is found or until
|
2012-08-03 19:53:20 +02:00
|
|
|
|
the end of the file is reached. To stop adding comments to rules, use a
|
2015-08-22 17:00:38 +02:00
|
|
|
|
line with only ?COMMENT.</para>
|
2012-12-23 00:47:03 +01:00
|
|
|
|
|
2011-10-02 20:45:55 +02:00
|
|
|
|
<para>The columns in the file are as follows (where the column name is
|
|
|
|
|
followed by a different name in parentheses, the different name is used in
|
|
|
|
|
the alternate specification syntax).</para>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
|
|
|
|
|
<variablelist>
|
2011-12-05 15:56:23 +01:00
|
|
|
|
<varlistentry>
|
|
|
|
|
<term><emphasis role="bold">ACTION</emphasis> - {<emphasis
|
|
|
|
|
role="bold">NOTRACK</emphasis>|<emphasis
|
2012-08-02 20:02:17 +02:00
|
|
|
|
role="bold">CT</emphasis>:<emphasis
|
|
|
|
|
role="bold">helper</emphasis>:<replaceable>name</replaceable>[(<replaceable>arg</replaceable>=<replaceable>val</replaceable>[,...])|<emphasis
|
2015-05-16 22:40:40 +02:00
|
|
|
|
role="bold">CT:ctevents:<replaceable>event</replaceable>[,...]|CT:expevents:new|notrack</emphasis>|DROP|LOG|NFLOG(<replaceable>nflog-parameters</replaceable>)|IP6TABLES(<replaceable>target</replaceable>)}[:<replaceable>log-level</replaceable>[:<replaceable>log-tag</replaceable>]][:<replaceable>chain-designator</replaceable>]</term>
|
2011-12-05 15:56:23 +01:00
|
|
|
|
|
|
|
|
|
<listitem>
|
2012-11-25 17:52:51 +01:00
|
|
|
|
<para>This column is only present when FORMAT >= 2. Values other
|
|
|
|
|
than NOTRACK require <firstterm>CT Target </firstterm>support in
|
|
|
|
|
your iptables and kernel.</para>
|
2011-12-05 22:51:18 +01:00
|
|
|
|
|
|
|
|
|
<itemizedlist>
|
|
|
|
|
<listitem>
|
2012-08-02 20:02:17 +02:00
|
|
|
|
<para><option>NOTRACK</option> or
|
|
|
|
|
<option>CT:notrack</option></para>
|
2011-12-05 22:51:18 +01:00
|
|
|
|
|
2013-12-31 20:04:43 +01:00
|
|
|
|
<para>Disables connection tracking for this packet. If a
|
|
|
|
|
<replaceable>log-level</replaceable> is specified, the packet
|
|
|
|
|
will also be logged at that level.</para>
|
2012-11-18 20:35:40 +01:00
|
|
|
|
</listitem>
|
|
|
|
|
|
2011-12-05 22:51:18 +01:00
|
|
|
|
<listitem>
|
|
|
|
|
<para><option>helper</option>:<replaceable>name</replaceable></para>
|
|
|
|
|
|
2012-08-02 20:02:17 +02:00
|
|
|
|
<para>Attach the helper identified by the
|
|
|
|
|
<replaceable>name</replaceable> to this connection. This is more
|
2013-12-31 20:04:43 +01:00
|
|
|
|
flexible than loading the conntrack helper with preset ports. If
|
|
|
|
|
a <replaceable>log-level</replaceable> is specified, the packet
|
|
|
|
|
will also be logged at that level.</para>
|
|
|
|
|
|
|
|
|
|
<para>At this writing, the available helpers are:</para>
|
|
|
|
|
|
|
|
|
|
<variablelist>
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>amanda</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Requires that the amanda netfilter helper is
|
|
|
|
|
present.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>ftp</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Requires that the FTP netfilter helper is
|
|
|
|
|
present.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>irc</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Requires that the IRC netfilter helper is
|
|
|
|
|
present.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>netbios-ns</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Requires that the netbios_ns (sic) helper is
|
|
|
|
|
present.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>RAS and Q.931</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>These require that the H323 netfilter helper is
|
|
|
|
|
present.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>pptp</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Requires that the pptp netfilter helper is
|
|
|
|
|
present.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>sane</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Requires that the SANE netfilter helper is
|
|
|
|
|
present.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>sip</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Requires that the SIP netfilter helper is
|
|
|
|
|
present.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>snmp</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Requires that the SNMP netfilter helper is
|
|
|
|
|
present.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>tftp</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Requires that the TFTP netfilter helper is
|
|
|
|
|
present.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
</variablelist>
|
|
|
|
|
|
|
|
|
|
<para>May be followed by an option list of
|
2012-08-02 20:02:17 +02:00
|
|
|
|
<replaceable>arg</replaceable>=<replaceable>val</replaceable>
|
|
|
|
|
pairs in parentheses:</para>
|
|
|
|
|
|
|
|
|
|
<itemizedlist>
|
|
|
|
|
<listitem>
|
|
|
|
|
<para><option>ctevents</option>=<replaceable>event</replaceable>[,...]</para>
|
|
|
|
|
|
|
|
|
|
<para>Only generate the specified conntrack events for this
|
|
|
|
|
connection. Possible event types are: <emphasis
|
|
|
|
|
role="bold">new</emphasis>, <emphasis
|
|
|
|
|
role="bold">related</emphasis>, <emphasis
|
|
|
|
|
role="bold">destroy</emphasis>, <emphasis
|
|
|
|
|
role="bold">reply</emphasis>, <emphasis
|
|
|
|
|
role="bold">assured</emphasis>, <emphasis
|
|
|
|
|
role="bold">protoinfo</emphasis>, <emphasis
|
|
|
|
|
role="bold">helper</emphasis>, <emphasis
|
|
|
|
|
role="bold">mark</emphasis> (this is connection mark, not
|
|
|
|
|
packet mark), <emphasis role="bold">natseqinfo</emphasis>,
|
2012-08-05 17:09:17 +02:00
|
|
|
|
and <emphasis role="bold">secmark</emphasis>. If more than
|
|
|
|
|
one <emphasis>event</emphasis> is listed, the
|
|
|
|
|
<replaceable>event</replaceable> list must be enclosed in
|
|
|
|
|
parentheses (e.g., ctevents=(new,related)).</para>
|
2012-08-02 20:02:17 +02:00
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para><option>expevents</option><option>=new</option></para>
|
|
|
|
|
|
2015-05-16 22:40:40 +02:00
|
|
|
|
<para>Only generate <emphasis role="bold">new</emphasis>
|
2012-08-02 20:02:17 +02:00
|
|
|
|
expectation events for this connection.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</itemizedlist>
|
2015-05-16 22:40:40 +02:00
|
|
|
|
</listitem>
|
2015-05-16 18:08:32 +02:00
|
|
|
|
|
2015-05-16 22:40:40 +02:00
|
|
|
|
<listitem>
|
|
|
|
|
<para>ctevents:<replaceable>event</replaceable>[,...]</para>
|
|
|
|
|
|
|
|
|
|
<para>Added in Shorewall 4.6.10. Only generate the specified
|
|
|
|
|
conntrack events for this connection. Possible event types are:
|
|
|
|
|
<emphasis role="bold">new</emphasis>, <emphasis
|
|
|
|
|
role="bold">related</emphasis>, <emphasis
|
|
|
|
|
role="bold">destroy</emphasis>, <emphasis
|
|
|
|
|
role="bold">reply</emphasis>, <emphasis
|
|
|
|
|
role="bold">assured</emphasis>, <emphasis
|
|
|
|
|
role="bold">protoinfo</emphasis>, <emphasis
|
|
|
|
|
role="bold">helper</emphasis>, <emphasis
|
|
|
|
|
role="bold">mark</emphasis> (this is connection mark, not packet
|
|
|
|
|
mark), <emphasis role="bold">natseqinfo</emphasis>, and
|
|
|
|
|
<emphasis role="bold">secmark</emphasis>.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>expevents=new</para>
|
|
|
|
|
|
|
|
|
|
<para>Added in Shorewall 4.6.10. Only generate <emphasis
|
|
|
|
|
role="bold">new</emphasis> expectation events for this
|
|
|
|
|
connection.</para>
|
2011-12-05 22:51:18 +01:00
|
|
|
|
</listitem>
|
2013-12-31 20:04:43 +01:00
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para><option>DROP</option></para>
|
|
|
|
|
|
|
|
|
|
<para>Added in Shorewall 4.5.10. Silently discard the packet. If
|
|
|
|
|
a <replaceable>log-level</replaceable> is specified, the packet
|
|
|
|
|
will also be logged at that level.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
2014-01-01 16:18:54 +01:00
|
|
|
|
<listitem>
|
|
|
|
|
<para><option>IP6TABLES</option>(<replaceable>target</replaceable>)</para>
|
|
|
|
|
|
|
|
|
|
<para>Added in Shorewall 4.6.0. Allows you to specify any
|
|
|
|
|
iptables <replaceable>target</replaceable> with target options
|
|
|
|
|
(e.g., "IP6TABLES(AUDIT --type drop)"). If the target is not one
|
|
|
|
|
recognized by Shorewall, the following error message will be
|
|
|
|
|
issued:</para>
|
|
|
|
|
|
|
|
|
|
<simplelist>
|
|
|
|
|
<member>ERROR: Unknown target
|
|
|
|
|
(<replaceable>target</replaceable>)</member>
|
|
|
|
|
</simplelist>
|
|
|
|
|
|
|
|
|
|
<para>This error message may be eliminated by adding
|
|
|
|
|
<replaceable>target</replaceable> as a builtin action in <ulink
|
2014-01-12 22:40:03 +01:00
|
|
|
|
url="/manpages6/shorewall6-actions.html">shorewall6-actions(5)</ulink>.</para>
|
2014-01-01 16:18:54 +01:00
|
|
|
|
</listitem>
|
|
|
|
|
|
2013-12-31 20:04:43 +01:00
|
|
|
|
<listitem>
|
|
|
|
|
<para><option>LOG</option></para>
|
|
|
|
|
|
|
|
|
|
<para>Added in Shoreawll 4.6.0. Logs the packet using the
|
|
|
|
|
specified <replaceable>log-level</replaceable> and<replaceable>
|
|
|
|
|
log-tag </replaceable>(if any). If no log-level is specified,
|
|
|
|
|
then 'info' is assumed.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para><option>NFLOG</option></para>
|
|
|
|
|
|
|
|
|
|
<para>Added in Shoreawll 4.6.0. Queues the packet to a backend
|
|
|
|
|
logging daemon using the NFLOG netfilter target with the
|
|
|
|
|
specified <replaceable>nflog-parameters</replaceable>.</para>
|
|
|
|
|
</listitem>
|
2011-12-05 22:51:18 +01:00
|
|
|
|
</itemizedlist>
|
2011-12-05 15:56:23 +01:00
|
|
|
|
|
|
|
|
|
<para>When FORMAT = 1, this column is not present and the rule is
|
|
|
|
|
processed as if NOTRACK had been entered in this column.</para>
|
2012-11-23 05:56:56 +01:00
|
|
|
|
|
2012-11-25 17:52:51 +01:00
|
|
|
|
<para>Beginning with Shorewall 4.5.10, when FORMAT = 3, this column
|
2012-11-23 05:56:56 +01:00
|
|
|
|
can end with a colon followed by a
|
|
|
|
|
<replaceable>chain-designator</replaceable>. The
|
|
|
|
|
<replaceable>chain-designator</replaceable> can be one of the
|
|
|
|
|
following:</para>
|
|
|
|
|
|
|
|
|
|
<variablelist>
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>P</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>The rule is added to the raw table PREROUTING chain.
|
|
|
|
|
This is the default if no
|
|
|
|
|
<replaceable>chain-designator</replaceable> is present.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>O</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>The rule is added to the raw table OUTPUT chain.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>PO or OP</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>The rule is added to the raw table PREROUTING and OUTPUT
|
|
|
|
|
chains.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
</variablelist>
|
2011-12-05 15:56:23 +01:00
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
2009-02-16 19:39:01 +01:00
|
|
|
|
<varlistentry>
|
2012-11-23 05:56:56 +01:00
|
|
|
|
<term>SOURCE (formats 1 and 2) ‒
|
2009-02-16 19:39:01 +01:00
|
|
|
|
<emphasis>zone</emphasis>[:<emphasis>interface</emphasis>][:<emphasis>address-list</emphasis>]</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>where <replaceable>zone</replaceable> is the name of a zone,
|
|
|
|
|
<replaceable>interface</replaceable> is an interface to that zone,
|
|
|
|
|
and <replaceable>address-list</replaceable> is a comma-separated
|
|
|
|
|
list of addresses (may contain exclusion - see <ulink
|
2014-01-12 22:40:03 +01:00
|
|
|
|
url="/manpages6/shorewall6-exclusion.html">shorewall6-exclusion</ulink>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
(5)).</para>
|
2012-08-03 19:53:20 +02:00
|
|
|
|
|
|
|
|
|
<para>Beginning with Shorewall 4.5.7, <option>all</option> can be
|
|
|
|
|
used as the <replaceable>zone</replaceable> name to mean
|
|
|
|
|
<firstterm>all zones</firstterm>.</para>
|
2012-11-21 22:07:01 +01:00
|
|
|
|
|
|
|
|
|
<para>Beginning with Shorewall 4.5.10, <option>all-</option> can be
|
|
|
|
|
used as the <replaceable>zone</replaceable> name to mean all
|
|
|
|
|
<firstterm>off-firewall zone</firstterm>s.</para>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
2012-11-23 05:56:56 +01:00
|
|
|
|
<varlistentry>
|
2016-12-11 01:22:47 +01:00
|
|
|
|
<term>SOURCE (format 3 prior to Shorewall 5.1.0) ‒
|
2012-11-26 16:48:43 +01:00
|
|
|
|
{-|<emphasis>interface</emphasis>[:<emphasis>address-list</emphasis>]|<replaceable>address-list</replaceable>}</term>
|
2012-11-23 05:56:56 +01:00
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Where <replaceable>interface</replaceable> is an interface to
|
|
|
|
|
that zone, and <replaceable>address-list</replaceable> is a
|
|
|
|
|
comma-separated list of addresses (may contain exclusion - see
|
2014-01-16 17:32:57 +01:00
|
|
|
|
<ulink
|
|
|
|
|
url="/manpages6/shorewall6-exclusion.html">shorewall6-exclusion</ulink>
|
2012-11-23 05:56:56 +01:00
|
|
|
|
(5)).</para>
|
|
|
|
|
|
|
|
|
|
<para>COMMENT is only allowed in format 1; the remainder of the line
|
|
|
|
|
is treated as a comment that will be associated with the generated
|
|
|
|
|
rule(s).</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
2009-02-16 19:39:01 +01:00
|
|
|
|
<varlistentry>
|
2016-12-11 01:22:47 +01:00
|
|
|
|
<term><emphasis role="bold">SOURCE (format 3 on Shorewall 5.1.0 and
|
|
|
|
|
later) -
|
|
|
|
|
{-|[<replaceable>source-spec</replaceable>[,...]]}</emphasis></term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>where <replaceable>source-spec</replaceable> is one of the
|
|
|
|
|
following:</para>
|
|
|
|
|
|
|
|
|
|
<variablelist>
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term><replaceable>interface</replaceable></term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Where interface is the logical name of an interface
|
|
|
|
|
defined in <ulink
|
|
|
|
|
url="shorewall-interfaces.html">shorewall-interface</ulink>(5).</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term><replaceable>address</replaceable>[,...][<replaceable>exclusion</replaceable>]</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>where <replaceable>address</replaceable> may be:</para>
|
|
|
|
|
|
|
|
|
|
<itemizedlist>
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>A host or network IP address.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>A MAC address in Shorewall format (preceded by a
|
|
|
|
|
tilde ("~") and using dash ("-") as a separator.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>The name of an ipset preceded by a plus sign ("+").
|
|
|
|
|
See <ulink
|
|
|
|
|
url="shorewall-ipsets.html">shorewall-ipsets</ulink>(5).</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</itemizedlist>
|
|
|
|
|
|
|
|
|
|
<para><replaceable>exclusion</replaceable> is described in
|
|
|
|
|
<ulink
|
|
|
|
|
url="/manpages/shorewall-exclusion.html">shorewall-exclusion</ulink>(5).</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term><replaceable>interface</replaceable>:<replaceable>address</replaceable>[,...][<replaceable>exclusion</replaceable>]</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>This form combines the preceding two and requires that
|
|
|
|
|
both the incoming interace and source address match.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term><replaceable>exclusion</replaceable></term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>See <ulink
|
|
|
|
|
url="/manpages/shorewall-exclusion.html">shorewall-exclusion</ulink>
|
|
|
|
|
(5)</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
</variablelist>
|
|
|
|
|
|
|
|
|
|
<para>Beginning with Shorewall 5.1.0, multiple
|
|
|
|
|
<replaceable>source-spec</replaceable>s separated by commas may be
|
|
|
|
|
specified provided that the following alternative forms are
|
|
|
|
|
used:</para>
|
|
|
|
|
|
|
|
|
|
<blockquote>
|
|
|
|
|
<para>(<replaceable>address</replaceable>[,...][<replaceable>exclusion</replaceable>])</para>
|
|
|
|
|
|
|
|
|
|
<para><replaceable>interface</replaceable>:(<replaceable>address</replaceable>[,...][<replaceable>exclusion</replaceable>])</para>
|
|
|
|
|
|
|
|
|
|
<para>(<replaceable>exclusion</replaceable>)</para>
|
|
|
|
|
</blockquote>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>DEST (Prior to Shorewall 5.1.0) ‒
|
2012-11-26 18:47:42 +01:00
|
|
|
|
{-|<emphasis>interface</emphasis>[:<emphasis>address-list</emphasis>]|<replaceable>address-list</replaceable>}</term>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>where <replaceable>address-list</replaceable> is a
|
|
|
|
|
comma-separated list of addresses (may contain exclusion - see
|
2014-01-16 17:32:57 +01:00
|
|
|
|
<ulink
|
|
|
|
|
url="/manpages6/shorewall6-exclusion.html">shorewall6-exclusion</ulink>
|
2012-11-26 18:47:42 +01:00
|
|
|
|
(5)).</para>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
2016-12-11 01:22:47 +01:00
|
|
|
|
<varlistentry>
|
|
|
|
|
<term><emphasis role="bold">DEST (Shorewall 5.1.0 and later) -
|
|
|
|
|
{-|<replaceable>dest-spec</replaceable>[,...]}</emphasis></term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>where <replaceable>dest-spec</replaceable> is one of the
|
|
|
|
|
following:</para>
|
|
|
|
|
|
|
|
|
|
<variablelist>
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term><replaceable>interface</replaceable></term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Where interface is the logical name of an interface
|
|
|
|
|
defined in <ulink
|
|
|
|
|
url="shorewall-interfaces.html">shorewall-interface</ulink>(5).</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term><replaceable>address</replaceable>[,...][<replaceable>exclusion</replaceable>]</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>where <replaceable>address</replaceable> may be:</para>
|
|
|
|
|
|
|
|
|
|
<itemizedlist>
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>A host or network IP address.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>A MAC address in Shorewall format (preceded by a
|
|
|
|
|
tilde ("~") and using dash ("-") as a separator.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>The name of an ipset preceded by a plus sign ("+").
|
|
|
|
|
See <ulink
|
|
|
|
|
url="shorewall-ipsets.html">shorewall-ipsets</ulink>(5).</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</itemizedlist>
|
|
|
|
|
|
|
|
|
|
<para><replaceable>exclusion</replaceable> is described in
|
|
|
|
|
<ulink
|
|
|
|
|
url="/manpages/shorewall-exclusion.html">shorewall-exclusion</ulink>(5).</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term><replaceable>interface</replaceable>:<replaceable>address</replaceable>[,...][<replaceable>exclusion</replaceable>]</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>This form combines the preceding two and requires that
|
|
|
|
|
both the outgoing interace and destination address
|
|
|
|
|
match.</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term><replaceable>exclusion</replaceable></term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>See <ulink
|
|
|
|
|
url="/manpages/shorewall-exclusion.html">shorewall-exclusion</ulink>
|
|
|
|
|
(5)</para>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
</variablelist>
|
|
|
|
|
|
|
|
|
|
<para>Beginning with Shorewall 5.1.0, multiple source-specs
|
|
|
|
|
separated by commas may be specified provided that the following
|
|
|
|
|
alternative forms are used:</para>
|
|
|
|
|
|
|
|
|
|
<blockquote>
|
|
|
|
|
<para>(<replaceable>address</replaceable>[,...][<replaceable>exclusion</replaceable>])</para>
|
|
|
|
|
|
|
|
|
|
<para><replaceable>interface</replaceable>:(<replaceable>address</replaceable>[,...][<replaceable>exclusion</replaceable>])</para>
|
|
|
|
|
|
|
|
|
|
<para>(<replaceable>exclusion</replaceable>)</para>
|
|
|
|
|
</blockquote>
|
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
2009-02-16 19:39:01 +01:00
|
|
|
|
<varlistentry>
|
|
|
|
|
<term>PROTO ‒
|
2013-01-08 01:06:54 +01:00
|
|
|
|
<replaceable>protocol-name-or-number</replaceable>[,...]</term>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>A protocol name from <filename>/etc/protocols</filename> or a
|
|
|
|
|
protocol number.</para>
|
2013-01-08 01:06:54 +01:00
|
|
|
|
|
|
|
|
|
<para>Beginning with Shorewall 4.5.12, this column can accept a
|
|
|
|
|
comma-separated list of protocols.</para>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
2015-12-04 23:53:26 +01:00
|
|
|
|
<term>DPORT -
|
2014-01-03 18:23:14 +01:00
|
|
|
|
{-|<replaceable>port-number/service-name-list</replaceable>|+<replaceable>ipset</replaceable>}</term>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>A comma-separated list of port numbers and/or service names
|
|
|
|
|
from <filename>/etc/services</filename>. May also include port
|
|
|
|
|
ranges of the form
|
|
|
|
|
<replaceable>low-port</replaceable>:<replaceable>high-port</replaceable>
|
|
|
|
|
if your kernel and iptables include port range support.</para>
|
2014-01-03 18:23:14 +01:00
|
|
|
|
|
|
|
|
|
<para>Beginning with Shorewall 4.6.0, an ipset name can be specified
|
|
|
|
|
in this column. This is intended to be used with
|
|
|
|
|
<firstterm>bitmap:port</firstterm> ipsets.</para>
|
2015-12-04 23:53:26 +01:00
|
|
|
|
|
|
|
|
|
<para>This column was formerly labelled DEST PORT(S).</para>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
2015-12-04 23:53:26 +01:00
|
|
|
|
<term>SPORT -
|
2014-01-03 18:23:14 +01:00
|
|
|
|
{-|<replaceable>port-number/service-name-list</replaceable>|+<replaceable>ipset</replaceable>}</term>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>A comma-separated list of port numbers and/or service names
|
|
|
|
|
from <filename>/etc/services</filename>. May also include port
|
|
|
|
|
ranges of the form
|
|
|
|
|
<replaceable>low-port</replaceable>:<replaceable>high-port</replaceable>
|
|
|
|
|
if your kernel and iptables include port range support.</para>
|
2013-03-04 18:56:10 +01:00
|
|
|
|
|
|
|
|
|
<para>Beginning with Shorewall 4.5.15, you may place '=' in this
|
2015-12-04 23:53:26 +01:00
|
|
|
|
column, provided that the DPORT column is non-empty. This causes the
|
|
|
|
|
rule to match when either the source port or the destination port in
|
|
|
|
|
a packet matches one of the ports specified in DPORT.</para>
|
2014-01-03 18:23:14 +01:00
|
|
|
|
|
|
|
|
|
<para>Beginning with Shorewall 4.6.0, an ipset name can be specified
|
|
|
|
|
in this column. This is intended to be used with
|
|
|
|
|
<firstterm>bitmap:port</firstterm> ipsets.</para>
|
2015-12-04 23:53:26 +01:00
|
|
|
|
|
|
|
|
|
<para>This column was formerly labelled SOURCE PORT(S).</para>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
|
|
<varlistentry>
|
2015-12-04 23:53:26 +01:00
|
|
|
|
<term>USER ‒
|
2009-02-16 19:39:01 +01:00
|
|
|
|
[<replaceable>user</replaceable>][:<replaceable>group</replaceable>]</term>
|
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>May only be specified if the SOURCE
|
|
|
|
|
<replaceable>zone</replaceable> is $FW. Specifies the effective user
|
|
|
|
|
id and or group id of the process sending the traffic.</para>
|
2015-12-04 23:53:26 +01:00
|
|
|
|
|
|
|
|
|
<para>This column was formerly labelled USER/GROUP.</para>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
2012-11-21 23:20:56 +01:00
|
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
|
<term><emphasis role="bold">SWITCH -
|
2012-11-28 01:17:43 +01:00
|
|
|
|
[!]<replaceable>switch-name</replaceable>[={0|1}]</emphasis></term>
|
2012-11-21 23:20:56 +01:00
|
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
|
<para>Added in Shorewall6 4.5.10 and allows enabling and disabling
|
|
|
|
|
the rule without requiring <command>shorewall6
|
|
|
|
|
restart</command>.</para>
|
|
|
|
|
|
|
|
|
|
<para>Enables the rule if the value stored in
|
|
|
|
|
<filename>/proc/net/nf_condition/<replaceable>switch-name</replaceable></filename>
|
|
|
|
|
is 1. Disables the rule if that file contains 0 (the default). If
|
|
|
|
|
'!' is supplied, the test is inverted such that the rule is enabled
|
2012-11-29 16:17:13 +01:00
|
|
|
|
if the file contains 0.</para>
|
|
|
|
|
|
2012-11-29 17:05:49 +01:00
|
|
|
|
<para>Within the <replaceable>switch-name</replaceable>, '@0' and
|
|
|
|
|
'@{0}' are replaced by the name of the chain to which the rule is a
|
|
|
|
|
added. The <replaceable>switch-name</replaceable> (after '@...'
|
|
|
|
|
expansion) must begin with a letter and be composed of letters,
|
|
|
|
|
decimal digits, underscores or hyphens. Switch names must be 30
|
|
|
|
|
characters or less in length.</para>
|
2012-11-21 23:20:56 +01:00
|
|
|
|
|
|
|
|
|
<para>Switches are normally <emphasis role="bold">off</emphasis>. To
|
|
|
|
|
turn a switch <emphasis role="bold">on</emphasis>:</para>
|
|
|
|
|
|
|
|
|
|
<simplelist>
|
|
|
|
|
<member><command>echo 1 >
|
|
|
|
|
/proc/net/nf_condition/<replaceable>switch-name</replaceable></command></member>
|
|
|
|
|
</simplelist>
|
|
|
|
|
|
|
|
|
|
<para>To turn it <emphasis role="bold">off</emphasis> again:</para>
|
|
|
|
|
|
|
|
|
|
<simplelist>
|
|
|
|
|
<member><command>echo 0 >
|
|
|
|
|
/proc/net/nf_condition/<replaceable>switch-name</replaceable></command></member>
|
|
|
|
|
</simplelist>
|
|
|
|
|
|
|
|
|
|
<para>Switch settings are retained over <command>shorewall6
|
|
|
|
|
restart</command>.</para>
|
2012-11-28 01:17:43 +01:00
|
|
|
|
|
|
|
|
|
<para>When the <replaceable>switch-name</replaceable> is followed by
|
|
|
|
|
<option>=0</option> or <option>=1</option>, then the switch is
|
2012-11-29 17:05:49 +01:00
|
|
|
|
initialized to off or on respectively by the
|
|
|
|
|
<command>start</command> command. Other commands do not affect the
|
|
|
|
|
switch setting.</para>
|
2012-11-21 23:20:56 +01:00
|
|
|
|
</listitem>
|
|
|
|
|
</varlistentry>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
</variablelist>
|
|
|
|
|
</refsect1>
|
|
|
|
|
|
2012-08-02 20:02:17 +02:00
|
|
|
|
<refsect1>
|
2012-11-23 05:56:56 +01:00
|
|
|
|
<title>EXAMPLES</title>
|
2012-08-02 20:02:17 +02:00
|
|
|
|
|
2012-11-23 05:56:56 +01:00
|
|
|
|
<para>Example 1:</para>
|
|
|
|
|
|
|
|
|
|
<para>Use the FTP helper for TCP port 21 connections from the firewall
|
|
|
|
|
itself.</para>
|
|
|
|
|
|
|
|
|
|
<programlisting>FORMAT 2
|
2015-12-04 23:53:26 +01:00
|
|
|
|
#ACTION SOURCE DEST PROTO DPORT SPORT USER
|
2012-08-02 20:02:17 +02:00
|
|
|
|
CT:helper:ftp(expevents=new) fw - tcp 21 </programlisting>
|
2012-11-23 05:56:56 +01:00
|
|
|
|
|
|
|
|
|
<para>Example 2 (Shorewall 4.5.10 or later):</para>
|
|
|
|
|
|
|
|
|
|
<para>Drop traffic to/from all zones to IP address 2001:1.2.3::4</para>
|
|
|
|
|
|
|
|
|
|
<programlisting>FORMAT 2
|
2015-12-04 23:53:26 +01:00
|
|
|
|
#ACTION SOURCE DEST PROTO DPORT SPORT USER
|
2012-11-23 05:56:56 +01:00
|
|
|
|
DROP all-:2001:1.2.3::4 -
|
|
|
|
|
DROP all 2001:1.2.3::4
|
|
|
|
|
</programlisting>
|
|
|
|
|
|
|
|
|
|
<para>or<programlisting>FORMAT 3
|
2015-12-04 23:53:26 +01:00
|
|
|
|
#ACTION SOURCE DEST PROTO DPORT SPORT USER
|
2012-11-23 05:56:56 +01:00
|
|
|
|
DROP:P 2001:1.2.3::4 -
|
|
|
|
|
DROP:PO - 2001:1.2.3::4
|
|
|
|
|
</programlisting></para>
|
2012-08-02 20:02:17 +02:00
|
|
|
|
</refsect1>
|
|
|
|
|
|
2009-02-16 19:39:01 +01:00
|
|
|
|
<refsect1>
|
|
|
|
|
<title>FILES</title>
|
|
|
|
|
|
|
|
|
|
<para>/etc/shorewall6/notrack</para>
|
|
|
|
|
</refsect1>
|
|
|
|
|
|
|
|
|
|
<refsect1>
|
|
|
|
|
<title>See ALSO</title>
|
|
|
|
|
|
2011-09-26 19:16:52 +02:00
|
|
|
|
<para><ulink
|
2014-01-12 22:40:03 +01:00
|
|
|
|
url="/configuration_file_basics.htm#Pairs">http://www.shorewall.net/configuration_file_basics.htm#Pairs</ulink></para>
|
2011-09-26 19:16:52 +02:00
|
|
|
|
|
2009-02-16 19:39:01 +01:00
|
|
|
|
<para>shorewall6(8), shorewall6-accounting(5), shorewall6-actions(5),
|
|
|
|
|
shorewall6-blacklist(5), shorewall6-hosts(5), shorewall6-interfaces(5),
|
2013-05-03 18:19:45 +02:00
|
|
|
|
shorewall6-ipsec(5), shorewall6-netmap(5),shorewall6-params(5),
|
2011-09-26 19:16:52 +02:00
|
|
|
|
shorewall6-policy(5), shorewall6-providers(5), shorewall6-proxyarp(5),
|
2012-08-02 20:02:17 +02:00
|
|
|
|
shorewall6-rtrules(5), shorewall6-routestopped(5), shorewall6-rules(5),
|
|
|
|
|
shorewall6.conf(5), shorewall6-secmarks(5), shorewall6-tcclasses(5),
|
2013-12-29 00:35:08 +01:00
|
|
|
|
shorewall6-tcdevices(5), shorewall6-mangle(5), shorewall6-tos(5),
|
2012-08-02 20:02:17 +02:00
|
|
|
|
shorewall6-tunnels(5), shorewall-zones(5)</para>
|
2009-02-16 19:39:01 +01:00
|
|
|
|
</refsect1>
|
|
|
|
|
</refentry>
|