2002-05-01 01:13:15 +02:00
|
|
|
#
|
2006-12-18 22:57:44 +01:00
|
|
|
# Shorewall version 3.4 - Modules File
|
2003-02-08 21:58:44 +01:00
|
|
|
#
|
2006-09-07 22:50:19 +02:00
|
|
|
# /usr/share/shorewall/modules
|
2003-02-08 21:58:44 +01:00
|
|
|
#
|
2005-08-02 18:46:30 +02:00
|
|
|
# This file loads the modules needed by the firewall.
|
|
|
|
#
|
|
|
|
# THE ORDER OF THE COMMANDS BELOW IS IMPORTANT!!!!!! You MUST load in
|
|
|
|
# dependency order. i.e., if M2 depends on M1 then you must load M1
|
|
|
|
# before you load M2.
|
|
|
|
#
|
|
|
|
# For additional information, see
|
|
|
|
# http://shorewall.net/Documentation.htm#modules
|
|
|
|
#
|
|
|
|
###############################################################################
|
2006-01-04 23:40:08 +01:00
|
|
|
#
|
|
|
|
# Essential Modules
|
|
|
|
#
|
2006-09-07 22:48:40 +02:00
|
|
|
loadmodule nfnetlink
|
|
|
|
loadmodule x_tables
|
2005-08-02 18:46:30 +02:00
|
|
|
loadmodule ip_tables
|
|
|
|
loadmodule iptable_filter
|
2006-03-09 17:40:21 +01:00
|
|
|
loadmodule iptable_mangle
|
2005-08-02 18:46:30 +02:00
|
|
|
loadmodule ip_conntrack
|
2006-03-09 17:40:21 +01:00
|
|
|
loadmodule iptable_nat
|
2006-09-07 22:48:40 +02:00
|
|
|
loadmodule xt_state
|
|
|
|
loadmodule xt_tcpudp
|
|
|
|
#
|
|
|
|
# Other xtables modules
|
|
|
|
#
|
|
|
|
loadmodule xt_CLASSIFY
|
|
|
|
loadmodule xt_connmark
|
|
|
|
loadmodule xt_CONNMARK
|
|
|
|
loadmodule xt_conntrack
|
|
|
|
loadmodule xt_dccp
|
|
|
|
loadmodule xt_helper
|
|
|
|
loadmodule xt_length
|
|
|
|
loadmodule xt_limit
|
|
|
|
loadmodule xt_mac
|
|
|
|
loadmodule xt_mark
|
|
|
|
loadmodule xt_MARK
|
|
|
|
loadmodule xt_NFQUEUE
|
|
|
|
loadmodule xt_physdev
|
|
|
|
loadmodule xt_pkttype
|
|
|
|
loadmodule xt_tcpmss
|
2006-01-04 23:40:08 +01:00
|
|
|
#
|
|
|
|
# Helpers
|
|
|
|
#
|
2005-08-02 18:46:30 +02:00
|
|
|
loadmodule ip_conntrack_ftp
|
|
|
|
loadmodule ip_conntrack_tftp
|
|
|
|
loadmodule ip_conntrack_irc
|
|
|
|
loadmodule iptable_nat
|
|
|
|
loadmodule ip_nat_ftp
|
|
|
|
loadmodule ip_nat_tftp
|
|
|
|
loadmodule ip_nat_irc
|
|
|
|
loadmodule ip_set
|
|
|
|
loadmodule ip_set_iphash
|
|
|
|
loadmodule ip_set_ipmap
|
|
|
|
loadmodule ip_set_macipmap
|
|
|
|
loadmodule ip_set_portmap
|
2006-01-04 23:40:08 +01:00
|
|
|
#
|
|
|
|
# Traffic Shaping
|
|
|
|
#
|
|
|
|
loadmodule sch_sfq
|
|
|
|
loadmodule sch_ingress
|
|
|
|
loadmodule sch_htb
|
|
|
|
loadmodule cls_u32
|
|
|
|
#
|
|
|
|
# Extensions
|
|
|
|
#
|
|
|
|
loadmodule ipt_addrtype
|
|
|
|
loadmodule ipt_ah
|
|
|
|
loadmodule ipt_CLASSIFY
|
|
|
|
loadmodule ipt_CLUSTERIP
|
|
|
|
loadmodule ipt_comment
|
|
|
|
loadmodule ipt_connmark
|
|
|
|
loadmodule ipt_CONNMARK
|
|
|
|
loadmodule ipt_conntrack
|
|
|
|
loadmodule ipt_dscp
|
|
|
|
loadmodule ipt_DSCP
|
|
|
|
loadmodule ipt_ecn
|
|
|
|
loadmodule ipt_ECN
|
|
|
|
loadmodule ipt_esp
|
|
|
|
loadmodule ipt_hashlimit
|
|
|
|
loadmodule ipt_helper
|
2006-02-10 20:33:31 +01:00
|
|
|
loadmodule ipt_ipp2p
|
2006-01-04 23:40:08 +01:00
|
|
|
loadmodule ipt_iprange
|
|
|
|
loadmodule ipt_length
|
|
|
|
loadmodule ipt_limit
|
|
|
|
loadmodule ipt_LOG
|
|
|
|
loadmodule ipt_mac
|
|
|
|
loadmodule ipt_mark
|
|
|
|
loadmodule ipt_MARK
|
|
|
|
loadmodule ipt_MASQUERADE
|
|
|
|
loadmodule ipt_multiport
|
|
|
|
loadmodule ipt_NETMAP
|
|
|
|
loadmodule ipt_NOTRACK
|
|
|
|
loadmodule ipt_owner
|
|
|
|
loadmodule ipt_physdev
|
|
|
|
loadmodule ipt_pkttype
|
|
|
|
loadmodule ipt_policy
|
|
|
|
loadmodule ipt_realm
|
|
|
|
loadmodule ipt_recent
|
|
|
|
loadmodule ipt_REDIRECT
|
|
|
|
loadmodule ipt_REJECT
|
|
|
|
loadmodule ipt_SAME
|
|
|
|
loadmodule ipt_sctp
|
2006-01-05 00:26:32 +01:00
|
|
|
loadmodule ipt_set
|
2006-01-04 23:40:08 +01:00
|
|
|
loadmodule ipt_state
|
|
|
|
loadmodule ipt_tcpmss
|
|
|
|
loadmodule ipt_TCPMSS
|
|
|
|
loadmodule ipt_tos
|
|
|
|
loadmodule ipt_TOS
|
|
|
|
loadmodule ipt_ttl
|
|
|
|
loadmodule ipt_TTL
|
|
|
|
loadmodule ipt_ULOG
|
2005-08-02 18:46:30 +02:00
|
|
|
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|