2008-12-09 17:50:17 +01:00
|
|
|
#
|
2008-12-13 20:30:23 +01:00
|
|
|
# Shorewall6 version 4 - Modules File
|
2008-12-09 17:50:17 +01:00
|
|
|
#
|
2008-12-13 20:30:23 +01:00
|
|
|
# /usr/share/shorewall6/modules
|
2008-12-09 17:50:17 +01:00
|
|
|
#
|
|
|
|
# This file loads the modules that may be needed by the firewall.
|
|
|
|
#
|
|
|
|
# THE ORDER OF THE COMMANDS BELOW IS IMPORTANT!!!!!! You MUST load in
|
|
|
|
# dependency order. i.e., if M2 depends on M1 then you must load M1
|
|
|
|
# before you load M2.
|
|
|
|
#
|
|
|
|
# If you need to modify this file, copy it to /etc/shorewall and modify the
|
|
|
|
# copy.
|
|
|
|
#
|
|
|
|
###############################################################################
|
|
|
|
#
|
|
|
|
# Essential Modules
|
|
|
|
#
|
|
|
|
loadmodule nfnetlink
|
|
|
|
loadmodule x_tables
|
2008-12-13 23:04:09 +01:00
|
|
|
loadmodule ip6_tables
|
|
|
|
loadmodule ip6table_filter
|
|
|
|
loadmodule ip6table_mangle
|
|
|
|
loadmodule ip6table_raw
|
2008-12-13 20:44:48 +01:00
|
|
|
loadmodule xt_conntrack
|
2008-12-13 20:30:23 +01:00
|
|
|
loadmodule nf_conntrack_ipv6
|
2008-12-09 17:50:17 +01:00
|
|
|
loadmodule xt_state
|
|
|
|
loadmodule xt_tcpudp
|
2008-12-13 23:04:09 +01:00
|
|
|
loadmodule ip6t_REJECT
|
|
|
|
loadmodule ip6t_LOG
|
2008-12-09 17:50:17 +01:00
|
|
|
#
|
|
|
|
# Other xtables modules
|
|
|
|
#
|
|
|
|
loadmodule xt_CLASSIFY
|
|
|
|
loadmodule xt_connmark
|
|
|
|
loadmodule xt_CONNMARK
|
|
|
|
loadmodule xt_conntrack
|
|
|
|
loadmodule xt_dccp
|
|
|
|
loadmodule xt_dscp
|
|
|
|
loadmodule xt_DSCP
|
|
|
|
loadmodule xt_hashlimit
|
|
|
|
loadmodule xt_helper
|
|
|
|
loadmodule xt_iprange
|
|
|
|
loadmodule xt_length
|
|
|
|
loadmodule xt_limit
|
|
|
|
loadmodule xt_mac
|
|
|
|
loadmodule xt_mark
|
|
|
|
loadmodule xt_MARK
|
|
|
|
loadmodule xt_multiport
|
|
|
|
loadmodule xt_NFQUEUE
|
|
|
|
loadmodule xt_owner
|
|
|
|
loadmodule xt_physdev
|
|
|
|
loadmodule xt_pkttype
|
2008-12-13 20:44:48 +01:00
|
|
|
loadmodule xt_policy
|
|
|
|
loadmodule xt_sctp
|
2008-12-09 17:50:17 +01:00
|
|
|
loadmodule xt_tcpmss
|
2008-12-13 20:44:48 +01:00
|
|
|
loadmodule xt_TCPMSS
|
|
|
|
loadmodule xt_time
|
2010-01-18 00:51:19 +01:00
|
|
|
loadmodule xt_IPMARK
|
|
|
|
loadmodule xt_TPROXY
|
2008-12-09 17:50:17 +01:00
|
|
|
#
|
|
|
|
# Helpers
|
|
|
|
#
|
2008-12-13 20:44:48 +01:00
|
|
|
loadmodule nf_conntrack_amanda
|
2008-12-09 17:50:17 +01:00
|
|
|
loadmodule nf_conntrack_ftp
|
|
|
|
loadmodule nf_conntrack_h323
|
|
|
|
loadmodule nf_conntrack_irc
|
|
|
|
loadmodule nf_conntrack_netbios_ns
|
2008-12-13 20:44:48 +01:00
|
|
|
loadmodule nf_conntrack_netbios_ns
|
2008-12-09 17:50:17 +01:00
|
|
|
loadmodule nf_conntrack_netlink
|
|
|
|
loadmodule nf_conntrack_pptp
|
2008-12-13 20:44:48 +01:00
|
|
|
loadmodule nf_conntrack_proto_sctp
|
|
|
|
loadmodule nf_conntrack_proto_udplite
|
|
|
|
loadmodule nf_conntrack_sane
|
|
|
|
loadmodule nf_conntrack_sip
|
|
|
|
loadmodule nf_conntrack_pptp
|
2008-12-09 17:50:17 +01:00
|
|
|
loadmodule nf_conntrack_proto_gre
|
|
|
|
loadmodule nf_conntrack_proto_sctp
|
|
|
|
loadmodule nf_conntrack_sip
|
|
|
|
loadmodule nf_conntrack_tftp
|
|
|
|
loadmodule nf_conntrack_sane
|
|
|
|
#
|
|
|
|
# Traffic Shaping
|
|
|
|
#
|
|
|
|
loadmodule sch_sfq
|
|
|
|
loadmodule sch_ingress
|
|
|
|
loadmodule sch_htb
|
|
|
|
loadmodule cls_u32
|
|
|
|
loadmodule cls_fw
|
2009-12-03 21:15:23 +01:00
|
|
|
loadmodule cls_flow
|
2008-12-09 17:50:17 +01:00
|
|
|
loadmodule act_police
|
|
|
|
#
|
|
|
|
# Extensions
|
|
|
|
#
|
2008-12-13 23:04:09 +01:00
|
|
|
loadmodule ip6_queue
|