mirror of
https://gitlab.com/shorewall/code.git
synced 2025-06-23 03:01:27 +02:00
Update My Network article for 5.0
Signed-off-by: Tom Eastep <teastep@shorewall.net>
This commit is contained in:
parent
d88a00d0cb
commit
6a8a229342
@ -531,7 +531,7 @@ smc:net ip #10.0.1.0/24
|
|||||||
<section id="interfaces">
|
<section id="interfaces">
|
||||||
<title>/etc/shorewall/interfaces</title>
|
<title>/etc/shorewall/interfaces</title>
|
||||||
|
|
||||||
<para><programlisting>#ZONE INTERFACE BROADCAST OPTIONS
|
<para><programlisting>#ZONE INTERFACE OPTIONS
|
||||||
loc INT_IF dhcp,physical=$INT_IF,ignore=1,wait=5,routefilter,nets=172.20.1.0/24,routeback,tcpflags=0
|
loc INT_IF dhcp,physical=$INT_IF,ignore=1,wait=5,routefilter,nets=172.20.1.0/24,routeback,tcpflags=0
|
||||||
net COMB_IF optional,sourceroute=0,routefilter=0,arp_ignore=1,proxyarp=0,physical=$COMB_IF,upnp,nosmurfs,tcpflags
|
net COMB_IF optional,sourceroute=0,routefilter=0,arp_ignore=1,proxyarp=0,physical=$COMB_IF,upnp,nosmurfs,tcpflags
|
||||||
net COMC_IF optional,sourceroute=0,routefilter=0,arp_ignore=1,proxyarp=0,physical=$COMC_IF,upnp,nosmurfs,tcpflags,dhcp
|
net COMC_IF optional,sourceroute=0,routefilter=0,arp_ignore=1,proxyarp=0,physical=$COMC_IF,upnp,nosmurfs,tcpflags,dhcp
|
||||||
@ -577,8 +577,7 @@ all all REJECT:Reject $LOG
|
|||||||
<section id="accounting">
|
<section id="accounting">
|
||||||
<title>/etc/shorewall/accounting</title>
|
<title>/etc/shorewall/accounting</title>
|
||||||
|
|
||||||
<para><programlisting>#ACTION CHAIN SOURCE DESTINATION PROTO DEST SOURCE USER/ MARK IPSEC
|
<para><programlisting>#ACTION CHAIN SOURCE DESTINATION PROTO DPORT SPORT USER MARK IPSEC
|
||||||
# PORT(S) PORT(S) GROUP
|
|
||||||
?COMMENT
|
?COMMENT
|
||||||
?SECTION PREROUTING
|
?SECTION PREROUTING
|
||||||
?SECTION INPUT
|
?SECTION INPUT
|
||||||
@ -604,7 +603,8 @@ ACCOUNT(loc-net,$INT_NET) - INT_IF COMB_IF
|
|||||||
<section id="blacklist">
|
<section id="blacklist">
|
||||||
<title>/etc/shorewall/blrules</title>
|
<title>/etc/shorewall/blrules</title>
|
||||||
|
|
||||||
<para><programlisting>WHITELIST net:70.90.191.126 all
|
<para><programlisting>#ACTION SOURCE DEST PROTO DPORT SPORT ORIGDEST RATE USER MARK CONNLIMIT TIME HEADERS SWITCH
|
||||||
|
WHITELIST net:70.90.191.126 all
|
||||||
BLACKLIST net:+blacklist all
|
BLACKLIST net:+blacklist all
|
||||||
BLACKLIST net all udp 1023:1033,1434,5948,23773
|
BLACKLIST net all udp 1023:1033,1434,5948,23773
|
||||||
DROP net all tcp 57,1433,1434,2401,2745,3127,3306,3410,4899,5554,5948,6101,8081,9898,23773
|
DROP net all tcp 57,1433,1434,2401,2745,3127,3306,3410,4899,5554,5948,6101,8081,9898,23773
|
||||||
@ -714,8 +714,7 @@ br0 70.90.191.120/29 70.90.191.121
|
|||||||
<title>/etc/shorewall/conntrack</title>
|
<title>/etc/shorewall/conntrack</title>
|
||||||
|
|
||||||
<para><programlisting>?FORMAT 2
|
<para><programlisting>?FORMAT 2
|
||||||
#ACTION SOURCE DESTINATION PROTO DEST SOURCE USER/
|
#ACTION SOURCE DEST PROTO DPORT SPORT
|
||||||
# PORT(S) PORT(S) GROUP
|
|
||||||
#
|
#
|
||||||
DROP net - udp 3551
|
DROP net - udp 3551
|
||||||
NOTRACK net - tcp 23
|
NOTRACK net - tcp 23
|
||||||
@ -832,9 +831,7 @@ ACCEPT COMC_IF $FW udp 67:68</programlistin
|
|||||||
<title>/etc/shorewall/rules</title>
|
<title>/etc/shorewall/rules</title>
|
||||||
|
|
||||||
<para><programlisting>################################################################################################################################################################################################
|
<para><programlisting>################################################################################################################################################################################################
|
||||||
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK CONNLIMIT TIME HEADERS SWITCH
|
#ACTION SOURCE DEST PROTO DPORT SPORT ORIGDEST RATE USER MARK CONNLIMIT TIME HEADERS SWITCH
|
||||||
# PORT(S) PORT(S) DEST LIMIT GROUP
|
|
||||||
################################################################################################################################################################################################
|
|
||||||
?if $VERSION < 40500
|
?if $VERSION < 40500
|
||||||
?SHELL echo " ERROR: Shorewall version is too low" >&2; exit 1
|
?SHELL echo " ERROR: Shorewall version is too low" >&2; exit 1
|
||||||
?endif
|
?endif
|
||||||
|
Loading…
x
Reference in New Issue
Block a user