2008-12-07 19:17:26 +01:00
|
|
|
#
|
2016-02-15 17:20:39 +01:00
|
|
|
# Shorewall -- /usr/share/shorewall/macro.SMB
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
2016-02-15 17:20:39 +01:00
|
|
|
# This macro handles Microsoft SMB traffic.
|
|
|
|
# You need to invoke this macro in both directions.
|
|
|
|
# Beware! This rule opens a lot of ports, and could possibly be used to
|
|
|
|
# compromise your firewall if not used with care. You should only allow SMB
|
|
|
|
# traffic between hosts you fully trust.
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
|
|
|
###############################################################################
|
2016-02-15 17:20:39 +01:00
|
|
|
#ACTION SOURCE DEST PROTO DPORT SPORT ORIGDEST RATE USER
|
|
|
|
|
2008-12-07 19:17:26 +01:00
|
|
|
PARAM - - udp 135,445
|
2012-08-09 16:36:04 +02:00
|
|
|
|
2012-08-12 16:25:11 +02:00
|
|
|
?if ( __CT_TARGET && ! $AUTOHELPERS && __NETBIOS_NS_HELPER )
|
2014-06-20 16:00:06 +02:00
|
|
|
PARAM - - udp 137 { helper=netbios-ns }
|
2012-08-09 16:36:04 +02:00
|
|
|
PARAM - - udp 138:139
|
2012-08-12 16:25:11 +02:00
|
|
|
?else
|
2012-08-09 16:36:04 +02:00
|
|
|
PARAM - - udp 137:139
|
2012-08-12 16:25:11 +02:00
|
|
|
?endif
|
2012-08-09 16:36:04 +02:00
|
|
|
|
2008-12-07 19:17:26 +01:00
|
|
|
PARAM - - udp 1024: 137
|
|
|
|
PARAM - - tcp 135,139,445
|