mirror of
https://gitlab.com/shorewall/code.git
synced 2025-02-22 20:51:15 +01:00
apply macro changes to trunk
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@7795 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
This commit is contained in:
parent
9212e83100
commit
0421f15d82
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
ACCEPT - - icmp fragmentation-needed
|
||||
ACCEPT - - icmp time-exceeded
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -9,7 +9,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 10080
|
||||
#
|
||||
# You may also need this rule. With AMANDA 2.4.4 on Linux kernel 2.6,
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 113
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 6881:6889
|
||||
#
|
||||
# It may also be necessary to allow UDP traffic:
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 2401
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 53
|
||||
PARAM - - tcp 53
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 3632
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -12,7 +12,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
#
|
||||
# Don't log 'auth' REJECT
|
||||
#
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
DROP - - udp - 53
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
DROP - - udp 1900
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -29,7 +29,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 4662
|
||||
PARAM - - udp 4665
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 21
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 79
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - 47 # GRE
|
||||
PARAM DEST SOURCE 47 # GRE
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 6346
|
||||
PARAM - - udp 6346
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 80
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 443
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 5190
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 143
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 993
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - 94 # IPIP
|
||||
PARAM DEST SOURCE 94 # IPIP
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 631
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -24,7 +24,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM SOURCE DEST tcp 631
|
||||
PARAM DEST SOURCE udp 631
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 500 500 # IKE
|
||||
PARAM - - 50 # ESP
|
||||
PARAM DEST SOURCE udp 500 500 # IKE
|
||||
|
@ -8,7 +8,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 500 500 # IKE
|
||||
PARAM - - 51 # AH
|
||||
PARAM DEST SOURCE udp 500 500 # IKE
|
||||
|
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 500 # IKE
|
||||
PARAM - - udp 4500 # NAT-T
|
||||
PARAM - - 50 # ESP
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#TARGET SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 5269
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#TARGET SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 5222
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#TARGET SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 5223
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 9100
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 1701 # L2TP
|
||||
PARAM DEST SOURCE udp 1701 # L2TP
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -12,6 +12,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 389
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -12,6 +12,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 636
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 3306
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 119
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 563
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 123
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -12,7 +12,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 123
|
||||
PARAM - - udp 1024: 123
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 5632
|
||||
PARAM - - tcp 5631
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 110
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 995 # Secure POP3
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - icmp 8
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 5432
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 515
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 3389
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -11,6 +11,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 37
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -13,7 +13,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
#
|
||||
# Don't log 'auth' REJECT
|
||||
#
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 873
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -11,7 +11,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 135,445
|
||||
PARAM - - udp 137:139
|
||||
PARAM - - udp 1024: 137
|
||||
|
@ -11,7 +11,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 135,445
|
||||
PARAM - - udp 137:139
|
||||
PARAM - - udp 1024: 137
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 901
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -15,6 +15,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 25
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -12,6 +12,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 465
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 161:162
|
||||
PARAM - - tcp 161
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 783
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 22
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 3690
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 3874 # Used for retrieving the tunnel information (eg by AICCU)
|
||||
PARAM - - udp 3740 # Used for signaling where the current IPv4 endpoint
|
||||
# of the tunnel is and that it is alive
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 587
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 514
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -9,6 +9,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 69
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 23
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 992
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -9,6 +9,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 37
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,7 +7,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - udp 33434:33524 # UDP Traceroute
|
||||
PARAM - - icmp 8 # ICMP Traceroute
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 5900:5909
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -8,6 +8,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 5500
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -9,7 +9,7 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 80 # HTTP (plaintext)
|
||||
PARAM - - tcp 443 # HTTPS (over SSL)
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 10000
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -7,6 +7,6 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
PARAM - - tcp 43
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
@ -15,7 +15,7 @@
|
||||
# - All entries in a macro undergo substitution when the macro is
|
||||
# invoked in the rules file.
|
||||
#
|
||||
# - Macros may not invoke other macros.
|
||||
# - Macros used in action bodies may not invoke other macros.
|
||||
#
|
||||
# The columns in the file are the same as those in the action.template file but
|
||||
# have different restrictions:
|
||||
@ -247,7 +247,7 @@
|
||||
# Otherwise, a separate rule will be generated for each
|
||||
# port.
|
||||
#
|
||||
# CLIENT PORT(S) (Optional) Port(s) used by the client. If omitted,
|
||||
# SOURCE PORT(S) (Optional) Port(s) used by the client. If omitted,
|
||||
# any source port is acceptable. Specified as a comma-
|
||||
# separated list of port names, port numbers or port
|
||||
# ranges.
|
||||
@ -305,19 +305,19 @@
|
||||
# /etc/shorewall/macro.FwdFTP:
|
||||
#
|
||||
# #ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||
# # PORT PORT(S) LIMIT GROUP
|
||||
# # PORT(S) PORT(S) LIMIT GROUP
|
||||
# DNAT - - tcp 21
|
||||
#
|
||||
# /etc/shorewall/rules:
|
||||
#
|
||||
# #ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/
|
||||
# # PORT PORT(S) DEST LIMIT GROUP
|
||||
# # PORT(S) PORT(S) DEST LIMIT GROUP
|
||||
# FwdFTP net loc:192.168.1.5
|
||||
#
|
||||
# The result is equivalent to:
|
||||
#
|
||||
# #ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/
|
||||
# # PORT PORT(S) DEST LIMIT GROUP
|
||||
# # PORT(S) PORT(S) DEST LIMIT GROUP
|
||||
# DNAT net loc:192.168.1.5 tcp 21
|
||||
#
|
||||
# The substitution rules are as follows:
|
||||
@ -348,7 +348,7 @@
|
||||
#
|
||||
# Example: ###############################################
|
||||
# #ACTION SOURCE DEST PROTO DEST
|
||||
# # PORT
|
||||
# # PORT(S)
|
||||
# macro.FTP File PARAM net loc tcp 21
|
||||
# rules File FTP/DNAT - 192.168.1.5
|
||||
# Result DNAT net loc:192.168.1.5 tcp 21
|
||||
@ -359,5 +359,5 @@
|
||||
#
|
||||
###############################################################################
|
||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||
# PORT PORT(S) LIMIT GROUP
|
||||
# PORT(S) PORT(S) LIMIT GROUP
|
||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
||||
|
Loading…
Reference in New Issue
Block a user