2008-12-07 19:17:26 +01:00
|
|
|
#
|
2016-02-15 17:20:39 +01:00
|
|
|
# Shorewall -- /usr/share/shorewall/macro.SANE
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
2016-02-15 17:20:39 +01:00
|
|
|
# This macro handles SANE network scanning.
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
|
|
|
###############################################################################
|
2016-02-15 17:20:39 +01:00
|
|
|
#ACTION SOURCE DEST PROTO DPORT SPORT ORIGDEST RATE USER
|
2012-08-09 16:36:04 +02:00
|
|
|
|
2012-08-12 16:25:11 +02:00
|
|
|
?if ( __CT_TARGET && ! $AUTOHELPERS && __SANE_HELPER )
|
2014-06-20 16:00:06 +02:00
|
|
|
PARAM - - tcp 6566 { helper=sane }
|
2012-08-12 16:25:11 +02:00
|
|
|
?else
|
2012-08-09 16:36:04 +02:00
|
|
|
PARAM - - tcp 6566
|
2012-08-12 16:25:11 +02:00
|
|
|
?endif
|
2012-08-09 16:36:04 +02:00
|
|
|
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
|
|
|
# Kernels 2.6.23+ has nf_conntrack_sane module which will handle
|
2016-02-15 17:20:39 +01:00
|
|
|
# sane data connection. If you need these, copy this file to /etc/shorewall
|
|
|
|
# and remove comments from one of the entries below.
|
2008-12-07 19:17:26 +01:00
|
|
|
#
|
|
|
|
# If you don't have sane conntracking support you need to open whole dynamic
|
|
|
|
# port range.
|
|
|
|
#
|
|
|
|
# This is for normal linux 2.4+
|
|
|
|
#PARAM - - tcp 32768:61000
|
|
|
|
# This is generic rule for any os running saned.
|
|
|
|
#PARAM - - tcp 1024:
|