2008-12-07 19:17:26 +01:00
|
|
|
#
|
2015-07-28 19:59:11 +02:00
|
|
|
# Shorewall version 5 - Actions.std File
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
|
|
|
# /usr/share/shorewall/actions.std
|
|
|
|
#
|
2019-03-25 19:11:51 +01:00
|
|
|
# Please see http://shorewall.org/Actions.html for additional
|
2008-12-07 19:17:26 +01:00
|
|
|
# information.
|
|
|
|
#
|
|
|
|
###############################################################################
|
|
|
|
#ACTION
|
2017-01-19 23:08:15 +01:00
|
|
|
A_REJECT noinline,logjump # Audits then rejects a connection request
|
|
|
|
A_REJECT! inline # Audits then rejects a connection request
|
2017-03-13 19:19:35 +01:00
|
|
|
AllowICMPs inline # Allow Required ICMP packets
|
2017-03-05 21:09:33 +01:00
|
|
|
allowBcast inline # Silently Allow Broadcast
|
|
|
|
allowinUPnP inline # Allow UPnP inbound (to firewall) traffic
|
2013-02-07 20:21:13 +01:00
|
|
|
allowInvalid inline # Accepts packets in the INVALID conntrack state
|
2017-03-05 21:09:33 +01:00
|
|
|
allowMcast inline # Silently Allow Multicast
|
2017-01-19 23:08:15 +01:00
|
|
|
AutoBL noinline # Auto-blacklist IPs that exceed thesholds
|
|
|
|
AutoBLL noinline # Helper for AutoBL
|
2017-01-24 00:03:02 +01:00
|
|
|
BLACKLIST logjump,section # Add sender to the dynamic blacklist
|
2017-10-20 17:49:14 +02:00
|
|
|
?if __ADDRTYPE
|
|
|
|
Broadcast inline,audit # Handles Broadcast/Anycast
|
|
|
|
?else
|
2017-02-15 19:16:20 +01:00
|
|
|
Broadcast noinline,audit # Handles Broadcast/Anycast
|
2017-10-20 17:49:14 +02:00
|
|
|
?endif
|
2017-12-02 19:45:06 +01:00
|
|
|
DNSAmp proto=17 # Matches one-question recursive DNS queries
|
2017-03-05 21:09:33 +01:00
|
|
|
dropBcast inline # Silently Drop Broadcast
|
2017-10-20 20:44:10 +02:00
|
|
|
dropBcasts inline # Silently Drop Broadcast
|
2013-02-07 20:21:13 +01:00
|
|
|
dropInvalid inline # Drops packets in the INVALID conntrack state
|
2017-03-05 21:09:33 +01:00
|
|
|
dropMcast inline # Silently Drop Multicast
|
2017-12-02 19:45:06 +01:00
|
|
|
dropNotSyn noinline,proto=6 # Silently Drop Non-syn TCP packets
|
|
|
|
DropDNSrep inline,proto=17 # Drops DNS replies
|
2017-01-19 23:08:15 +01:00
|
|
|
DropSmurfs noinline # Drop smurf packets
|
2016-03-14 22:54:09 +01:00
|
|
|
Established inline,\ # Handles packets in the ESTABLISHED state
|
2017-01-19 23:08:15 +01:00
|
|
|
state=ESTABLISHED #
|
2017-12-05 19:21:16 +01:00
|
|
|
FIN inline,audit,\ # Handles ACK,FIN packets
|
2017-12-02 19:45:06 +01:00
|
|
|
proto=6
|
2017-03-05 21:09:33 +01:00
|
|
|
forwardUPnP noinline # Allow traffic that upnpd has redirected from 'upnp' interfaces.
|
2015-09-19 21:31:54 +02:00
|
|
|
GlusterFS inline # Handles GlusterFS
|
2017-01-19 23:08:15 +01:00
|
|
|
IfEvent noinline # Perform an action based on an event
|
|
|
|
Invalid inline,audit,\ # Handles packets in the INVALID conntrack state
|
|
|
|
state=INVALID #
|
2017-03-05 21:09:33 +01:00
|
|
|
Limit noinline # Limit the rate of connections from each individual IP address
|
2017-10-20 21:01:41 +02:00
|
|
|
?if __ADDRTYPE
|
|
|
|
Multicast inline,audit # Handles Multicast
|
|
|
|
?else
|
2017-02-15 19:16:20 +01:00
|
|
|
Multicast noinline,audit # Handles Multicast
|
2017-10-20 21:01:41 +02:00
|
|
|
?endif
|
2016-03-14 22:54:09 +01:00
|
|
|
New inline,state=NEW # Handles packets in the NEW conntrack state
|
2017-12-02 19:45:06 +01:00
|
|
|
NotSyn inline,audit,\ # Handles TCP packets which do not have SYN=1 and ACK=0
|
|
|
|
proto=6
|
|
|
|
rejNotSyn noinline,proto=6 # Silently Reject Non-syn TCP packets
|
2017-01-19 23:08:15 +01:00
|
|
|
Related inline,\ # Handles packets in the RELATED conntrack state
|
|
|
|
state=RELATED #
|
2013-07-11 19:39:21 +02:00
|
|
|
ResetEvent inline # Reset an Event
|
2017-12-02 19:45:06 +01:00
|
|
|
RST inline,audit,\ # Handle packets with RST set
|
|
|
|
proto=6
|
2013-07-11 19:39:21 +02:00
|
|
|
SetEvent inline # Initialize an event
|
2017-12-02 19:45:06 +01:00
|
|
|
TCPFlags proto=6 # Handle bad flag combinations.
|
2017-01-19 23:08:15 +01:00
|
|
|
Untracked inline,\ # Handles packets in the UNTRACKED conntrack state
|
|
|
|
state=UNTRACKED #
|