2008-12-07 19:17:26 +01:00
|
|
|
#
|
|
|
|
# Shorewall version 4 - IPsecnat Macro
|
|
|
|
#
|
|
|
|
# /usr/share/shorewall/macro.IPsecnat
|
|
|
|
#
|
|
|
|
# This macro (bidirectional) handles IPsec traffic and Nat-Traversal
|
|
|
|
#
|
|
|
|
###############################################################################
|
2014-05-07 21:19:24 +02:00
|
|
|
?FORMAT 2
|
|
|
|
###############################################################################
|
|
|
|
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGIN RATE USER/
|
|
|
|
# PORT(S) PORT(S) DEST LIMIT GROUP
|
2008-12-07 19:17:26 +01:00
|
|
|
PARAM - - udp 500 # IKE
|
|
|
|
PARAM - - udp 4500 # NAT-T
|
|
|
|
PARAM - - 50 # ESP
|
|
|
|
PARAM DEST SOURCE udp 500 # IKE
|
|
|
|
PARAM DEST SOURCE udp 4500 # NAT-T
|
|
|
|
PARAM DEST SOURCE 50 # ESP
|