forked from extern/shorewall_code
Update My Network article for 5.0
Signed-off-by: Tom Eastep <teastep@shorewall.net>
This commit is contained in:
parent
d88a00d0cb
commit
6a8a229342
@ -531,7 +531,7 @@ smc:net ip #10.0.1.0/24
|
||||
<section id="interfaces">
|
||||
<title>/etc/shorewall/interfaces</title>
|
||||
|
||||
<para><programlisting>#ZONE INTERFACE BROADCAST OPTIONS
|
||||
<para><programlisting>#ZONE INTERFACE OPTIONS
|
||||
loc INT_IF dhcp,physical=$INT_IF,ignore=1,wait=5,routefilter,nets=172.20.1.0/24,routeback,tcpflags=0
|
||||
net COMB_IF optional,sourceroute=0,routefilter=0,arp_ignore=1,proxyarp=0,physical=$COMB_IF,upnp,nosmurfs,tcpflags
|
||||
net COMC_IF optional,sourceroute=0,routefilter=0,arp_ignore=1,proxyarp=0,physical=$COMC_IF,upnp,nosmurfs,tcpflags,dhcp
|
||||
@ -577,8 +577,7 @@ all all REJECT:Reject $LOG
|
||||
<section id="accounting">
|
||||
<title>/etc/shorewall/accounting</title>
|
||||
|
||||
<para><programlisting>#ACTION CHAIN SOURCE DESTINATION PROTO DEST SOURCE USER/ MARK IPSEC
|
||||
# PORT(S) PORT(S) GROUP
|
||||
<para><programlisting>#ACTION CHAIN SOURCE DESTINATION PROTO DPORT SPORT USER MARK IPSEC
|
||||
?COMMENT
|
||||
?SECTION PREROUTING
|
||||
?SECTION INPUT
|
||||
@ -604,7 +603,8 @@ ACCOUNT(loc-net,$INT_NET) - INT_IF COMB_IF
|
||||
<section id="blacklist">
|
||||
<title>/etc/shorewall/blrules</title>
|
||||
|
||||
<para><programlisting>WHITELIST net:70.90.191.126 all
|
||||
<para><programlisting>#ACTION SOURCE DEST PROTO DPORT SPORT ORIGDEST RATE USER MARK CONNLIMIT TIME HEADERS SWITCH
|
||||
WHITELIST net:70.90.191.126 all
|
||||
BLACKLIST net:+blacklist all
|
||||
BLACKLIST net all udp 1023:1033,1434,5948,23773
|
||||
DROP net all tcp 57,1433,1434,2401,2745,3127,3306,3410,4899,5554,5948,6101,8081,9898,23773
|
||||
@ -714,8 +714,7 @@ br0 70.90.191.120/29 70.90.191.121
|
||||
<title>/etc/shorewall/conntrack</title>
|
||||
|
||||
<para><programlisting>?FORMAT 2
|
||||
#ACTION SOURCE DESTINATION PROTO DEST SOURCE USER/
|
||||
# PORT(S) PORT(S) GROUP
|
||||
#ACTION SOURCE DEST PROTO DPORT SPORT
|
||||
#
|
||||
DROP net - udp 3551
|
||||
NOTRACK net - tcp 23
|
||||
@ -832,9 +831,7 @@ ACCEPT COMC_IF $FW udp 67:68</programlistin
|
||||
<title>/etc/shorewall/rules</title>
|
||||
|
||||
<para><programlisting>################################################################################################################################################################################################
|
||||
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK CONNLIMIT TIME HEADERS SWITCH
|
||||
# PORT(S) PORT(S) DEST LIMIT GROUP
|
||||
################################################################################################################################################################################################
|
||||
#ACTION SOURCE DEST PROTO DPORT SPORT ORIGDEST RATE USER MARK CONNLIMIT TIME HEADERS SWITCH
|
||||
?if $VERSION < 40500
|
||||
?SHELL echo " ERROR: Shorewall version is too low" >&2; exit 1
|
||||
?endif
|
||||
|
Loading…
Reference in New Issue
Block a user