shorewall_code/Shorewall/Macros/macro.SANE
Tom Eastep e84ee76c7d Add helpers to macros
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2012-08-09 10:32:34 -07:00

30 lines
725 B
Plaintext

#
# Shorewall version 4 - SANE Macro
#
# /usr/share/shorewall/macro.SANE
#
# This macro handles SANE network scanning.
#
###############################################################################
FORMAT 2
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
# PORT(S) PORT(S) LIMIT GROUP
?IF ( __CT_TARGET && $HELPERS && __SANE_HELPER )
PARAM - - tcp 6566 ; helper=sane
?ELSE
PARAM - - tcp 6566
?ENDIF
#
# Kernels 2.6.23+ has nf_conntrack_sane module which will handle
# sane data connection.
#
# If you don't have sane conntracking support you need to open whole dynamic
# port range.
#
# This is for normal linux 2.4+
#PARAM - - tcp 32768:61000
# This is generic rule for any os running saned.
#PARAM - - tcp 1024: