forked from extern/shorewall_code
Compare commits
375 Commits
4.4.0-RC2
...
4.4.4-base
Author | SHA1 | Date | |
---|---|---|---|
|
bce4d51a18 | ||
|
c5bb493b29 | ||
|
0df84cf8b5 | ||
|
a23632f45e | ||
|
de9c088972 | ||
|
c26fe6b15e | ||
|
c39a9fb5eb | ||
|
d7c084c9c6 | ||
|
4579a71574 | ||
|
831611e792 | ||
|
5f70b261b6 | ||
|
c4bfab29a5 | ||
|
9d5dd2ad3a | ||
|
5ec4f8d82c | ||
|
2a910ebddf | ||
|
31f01fe765 | ||
|
016537f631 | ||
|
dd543a2934 | ||
|
f5a019becc | ||
|
20ef4e584b | ||
|
1c1f16661f | ||
|
cb67513160 | ||
|
b662718eec | ||
|
10affb1cde | ||
|
fa3bdde214 | ||
|
9d57ff050a | ||
|
0e6c9abb5b | ||
|
f904866336 | ||
|
2d53f8cb0c | ||
|
e748341afd | ||
|
b943f09e37 | ||
|
8ddc2e804d | ||
|
4e6b8f8f42 | ||
|
0f078e7440 | ||
|
a4eb581d44 | ||
|
06d3b2c692 | ||
|
6987cd15c5 | ||
|
ba8ad6346a | ||
|
893a847c87 | ||
|
1735e168b1 | ||
|
bd9c651961 | ||
|
bf8c38e054 | ||
|
7120a73f0e | ||
|
c9e57c93a2 | ||
|
4e2f2923b6 | ||
|
79b5cb49df | ||
|
893a0c9d42 | ||
|
9b127e6e06 | ||
|
92208251b7 | ||
|
dda6f06883 | ||
|
4d977306f9 | ||
|
83621ff416 | ||
|
09f1b6501c | ||
|
ca1dd1416d | ||
|
1238b771a2 | ||
|
b1706e10e3 | ||
|
bcd4887d84 | ||
|
7f54a6fea9 | ||
|
496cfc391e | ||
|
b491745f1c | ||
|
4ef45ff665 | ||
|
73eab1fa55 | ||
|
d73ebb8a6a | ||
|
7014bd3ea0 | ||
|
89bdcf9a3d | ||
|
a98195e156 | ||
|
fb3477b8b5 | ||
|
c1898d1c80 | ||
|
7e21488aec | ||
|
b4199fd068 | ||
|
28b660c853 | ||
|
3cc9ee7be5 | ||
|
4548db58da | ||
|
4f5c602d5f | ||
|
25549b176c | ||
|
306549119a | ||
|
5a525134ea | ||
|
f2f91ce7dd | ||
|
c893ba6ffa | ||
|
1892160ed5 | ||
|
45653ffe79 | ||
|
f97e0c5989 | ||
|
11ddfa92e9 | ||
|
23d0806da2 | ||
|
99c77d2611 | ||
|
4c3b0c7571 | ||
|
59d01ccf97 | ||
|
105754823a | ||
|
f0b4b1f42e | ||
|
cc0adc218f | ||
|
8251948d2a | ||
|
b3571261dd | ||
|
c922afaf23 | ||
|
3e2cf982a3 | ||
|
86df82a29a | ||
|
46896e7dce | ||
|
445527d27e | ||
|
58ef1d3b63 | ||
|
d0cda6b6ea | ||
|
49f361124e | ||
|
c4af105ee4 | ||
|
7adb9b12bb | ||
|
a0482132c6 | ||
|
abc9ab061a | ||
|
65e4a5ff66 | ||
|
0a74320bc2 | ||
|
31bbec0fdd | ||
|
30dbfdc949 | ||
|
f3043f1453 | ||
|
e6755b7172 | ||
|
f6913953fe | ||
|
a61c9a9e06 | ||
|
62c7ad7fbb | ||
|
b38841798e | ||
|
44c5ebcfa4 | ||
|
6e6063f193 | ||
|
e2f64af187 | ||
|
19a90db09f | ||
|
94d039bf56 | ||
|
b24544306c | ||
|
990a9f0fdc | ||
|
1b0a3e4417 | ||
|
80f41779f8 | ||
|
fe3b8be029 | ||
|
f1d014dfe4 | ||
|
7064b8dd08 | ||
|
7612c895e5 | ||
|
3f7a1f9574 | ||
|
28b0e99492 | ||
|
83a9d8dd1b | ||
|
dc643c67e9 | ||
|
ab4e7cffcf | ||
|
8089ef1599 | ||
|
8915145607 | ||
|
beac09e45f | ||
|
de933ba912 | ||
|
964cba79a9 | ||
|
065808be16 | ||
|
3171d3bfc2 | ||
|
a87cb7b95d | ||
|
a8cc7d2a7e | ||
|
dd70456430 | ||
|
ddb46931a0 | ||
|
327e170be5 | ||
|
5e49be219b | ||
|
d323c5b9c5 | ||
|
39ee3b2025 | ||
|
393673a884 | ||
|
bfdc8db31a | ||
|
c1305eb059 | ||
|
9f853d02d9 | ||
|
111464ad95 | ||
|
795ffb7212 | ||
|
d84458518e | ||
|
428c3d1e4e | ||
|
20250c9ce9 | ||
|
96b19dd218 | ||
|
120aade417 | ||
|
4f4925002a | ||
|
728ad2fecf | ||
|
0d651f093b | ||
|
326ac90596 | ||
|
d6b641b000 | ||
|
a5f3a05341 | ||
|
0e8cb3b74d | ||
|
8180f45382 | ||
|
f25646d819 | ||
|
b8e772a416 | ||
|
d5d4c451f9 | ||
|
9f102a1fba | ||
|
e814dc7b75 | ||
|
e1f7048107 | ||
|
485ddd5e9f | ||
|
6afc43d200 | ||
|
8fdbb6f252 | ||
|
5793246d7c | ||
|
57f4458ec9 | ||
|
8fdebf0c38 | ||
|
904754c074 | ||
|
66765dcf75 | ||
|
07d8872823 | ||
|
9b0a9e8ecd | ||
|
0336a77120 | ||
|
95d422b15f | ||
|
6f54b5ea2f | ||
|
8c2a228a7d | ||
|
460428b21a | ||
|
02d9888513 | ||
|
f33e842f1b | ||
|
82eaf124ca | ||
|
74aff4f4ef | ||
|
212937a29d | ||
|
7c1dd35a00 | ||
|
0b03f52ad9 | ||
|
5fc0137a2e | ||
|
128edd4bba | ||
|
b4712a93fa | ||
|
bb83db3eb9 | ||
|
5655dbb01b | ||
|
fefff9fd83 | ||
|
9a1cb0c6b6 | ||
|
b2c7b583f5 | ||
|
bc7e65732e | ||
|
993bbe8a4e | ||
|
1ef90b4f0f | ||
|
8da5fd42d0 | ||
|
180024c1fc | ||
|
06e85d6191 | ||
|
c4eeb7b77e | ||
|
b03d502bbb | ||
|
cf9bb616b8 | ||
|
70ebe17cb3 | ||
|
477c0ef9e8 | ||
|
1a33596ada | ||
|
efa952572c | ||
|
7192b47289 | ||
|
75eb186ea7 | ||
|
f126755a96 | ||
|
ec94ed638e | ||
|
496a9449f1 | ||
|
4368af9525 | ||
|
b092ba5671 | ||
|
dd64ea2484 | ||
|
bb8ad187f1 | ||
|
03821dc22c | ||
|
76d9a80df3 | ||
|
84bff13e7f | ||
|
4a809e14ab | ||
|
f3455b107d | ||
|
df5291e119 | ||
|
015d4f58ce | ||
|
4412a05a70 | ||
|
62b1dbcd7f | ||
|
c9e9877f05 | ||
|
9e09e61a1a | ||
|
b778f04b1a | ||
|
b30da86cce | ||
|
0a39672b46 | ||
|
3647b801dc | ||
|
fbfa4b4e49 | ||
|
1544c0b2b1 | ||
|
d368d80a12 | ||
|
5297bb8b8d | ||
|
9ef0dcb221 | ||
|
2bb92a79f3 | ||
|
57ca3591e5 | ||
|
75232c6f10 | ||
|
3f9e1ced7d | ||
|
d31721a066 | ||
|
b4f7b85b3b | ||
|
b7915991ba | ||
|
a0a9e087de | ||
|
84fab0ebda | ||
|
1ef00c547b | ||
|
f2c3d9cd79 | ||
|
4809314fc1 | ||
|
acfdc7e481 | ||
|
a62d86aca7 | ||
|
5db7e77462 | ||
|
44803c1212 | ||
|
b5bf7f5c47 | ||
|
1ab2c5b2c0 | ||
|
8d447ebfba | ||
|
f7772505e5 | ||
|
140b8ffc3a | ||
|
a9c3e6f80a | ||
|
c680b5820b | ||
|
383f3e8bcf | ||
|
608d7b11da | ||
|
f106613300 | ||
|
52dfd5b259 | ||
|
db803807a7 | ||
|
b81f176680 | ||
|
e6dc40f2f4 | ||
|
1b26c65cbc | ||
|
8932106394 | ||
|
53ab9427fc | ||
|
088e164f18 | ||
|
4eb9e5db3d | ||
|
679cff2779 | ||
|
6b5493b81c | ||
|
e24dbb9aea | ||
|
267bc808f5 | ||
|
5ac331a5a0 | ||
|
65c59a36db | ||
|
b72e8f6f4d | ||
|
f71e6f87f1 | ||
|
5dd41249c6 | ||
|
8c16ac1d46 | ||
|
ddf8bbe516 | ||
|
dd1baf4beb | ||
|
f1d12d193b | ||
|
82cd525658 | ||
|
2d404fa998 | ||
|
622db3655f | ||
|
4bc1fb145a | ||
|
897748aa83 | ||
|
be574ea426 | ||
|
1cf22ead7f | ||
|
bb6e9af43a | ||
|
90b0bedc43 | ||
|
787a1867a0 | ||
|
49a2ff05ce | ||
|
e756689d0c | ||
|
89a6d7e5db | ||
|
bc1dbb3d4e | ||
|
d8cc9c5c92 | ||
|
6d2809f154 | ||
|
400a1ed647 | ||
|
0557148bec | ||
|
cbc9fa6e4c | ||
|
201145eed9 | ||
|
c908edab34 | ||
|
55f75604b3 | ||
|
f042c641d6 | ||
|
9b87812531 | ||
|
883f415e53 | ||
|
e2bfcef5af | ||
|
45446bc754 | ||
|
8161e54bea | ||
|
09b9bfa914 | ||
|
7211569197 | ||
|
0909bcc28f | ||
|
302b6db831 | ||
|
b05255e2e9 | ||
|
336d4f29f9 | ||
|
f88de91dd9 | ||
|
4917ddee38 | ||
|
2bac824207 | ||
|
f056faa6c4 | ||
|
5cb9ff0009 | ||
|
51e7bcdaf4 | ||
|
49554c5d7d | ||
|
c026c3d75e | ||
|
ef7fe8166a | ||
|
33c3a27960 | ||
|
3e7c7a7e90 | ||
|
3cf02bd617 | ||
|
b7a6223f44 | ||
|
6a25d6b9db | ||
|
1d1133532f | ||
|
1a5027de9f | ||
|
1051c44f51 | ||
|
8011a61970 | ||
|
a4090dc34f | ||
|
55c879e4e6 | ||
|
c34e09cd67 | ||
|
374aceb06c | ||
|
7fbfb61fee | ||
|
429178d162 | ||
|
fd75bc728a | ||
|
ed1e1f1352 | ||
|
51e70ee1e8 | ||
|
a069b8817c | ||
|
b612336b95 | ||
|
71fb62c760 | ||
|
b92730554e | ||
|
88c389e186 | ||
|
3af3ce6779 | ||
|
0c0026db53 | ||
|
a6d382331d | ||
|
9fd25a4832 | ||
|
031afd59b5 | ||
|
70f46c02cc | ||
|
9ce5887269 | ||
|
e91d3dd905 | ||
|
1219397a74 | ||
|
02b950dc9e | ||
|
dd5a73d678 | ||
|
46ba12a915 | ||
|
999a00dc77 | ||
|
3efaef813f | ||
|
8c5a41f1fc | ||
|
5ded978c07 | ||
|
0e09292587 |
@@ -10,10 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-interfaces"
|
# For information about entries in this file, type "man shorewall-interfaces"
|
||||||
#
|
|
||||||
# For additional information, see
|
|
||||||
# http://shorewall.net/Documentation.htm#Interfaces
|
|
||||||
#
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
#ZONE INTERFACE BROADCAST OPTIONS
|
#ZONE INTERFACE BROADCAST OPTIONS
|
||||||
net eth0 detect dhcp,tcpflags,logmartians,nosmurfs
|
net eth0 detect dhcp,tcpflags,logmartians,nosmurfs
|
||||||
|
@@ -10,9 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#-----------------------------------------------------------------------------
|
#-----------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-policy"
|
# For information about entries in this file, type "man shorewall-policy"
|
||||||
#
|
|
||||||
# See http://shorewall.net/Documentation.htm#Policy for additional information.
|
|
||||||
#
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
#SOURCE DEST POLICY LOG LEVEL LIMIT:BURST
|
#SOURCE DEST POLICY LOG LEVEL LIMIT:BURST
|
||||||
$FW net ACCEPT
|
$FW net ACCEPT
|
||||||
|
@@ -10,16 +10,13 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------------------------------------
|
||||||
# For information on entries in this file, type "man shorewall-rules"
|
# For information on entries in this file, type "man shorewall-rules"
|
||||||
#
|
|
||||||
# For more information, see http://www.shorewall.net/Documentation.htm#Zones
|
|
||||||
#
|
|
||||||
#############################################################################################################
|
#############################################################################################################
|
||||||
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK
|
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK
|
||||||
# PORT PORT(S) DEST LIMIT GROUP
|
# PORT PORT(S) DEST LIMIT GROUP
|
||||||
|
|
||||||
# Drop Ping from the "bad" net zone.. and prevent your log from being flooded..
|
# Drop Ping from the "bad" net zone.. and prevent your log from being flooded..
|
||||||
|
|
||||||
Ping/DROP net $FW
|
Ping(DROP) net $FW
|
||||||
|
|
||||||
# Permit all ICMP traffic FROM the firewall TO the net zone
|
# Permit all ICMP traffic FROM the firewall TO the net zone
|
||||||
|
|
||||||
|
@@ -34,9 +34,9 @@ VERBOSITY=1
|
|||||||
|
|
||||||
LOGFILE=/var/log/messages
|
LOGFILE=/var/log/messages
|
||||||
|
|
||||||
STARTUP_LOG=
|
STARTUP_LOG=/var/log/shorewall-init.log
|
||||||
|
|
||||||
LOG_VERBOSITY=
|
LOG_VERBOSITY=2
|
||||||
|
|
||||||
LOGFORMAT="Shorewall:%s:%s:"
|
LOGFORMAT="Shorewall:%s:%s:"
|
||||||
|
|
||||||
@@ -107,7 +107,7 @@ RCP_COMMAND='scp ${files} ${root}@${system}:${destination}'
|
|||||||
# F I R E W A L L O P T I O N S
|
# F I R E W A L L O P T I O N S
|
||||||
###############################################################################
|
###############################################################################
|
||||||
|
|
||||||
IP_FORWARDING=On
|
IP_FORWARDING=Off
|
||||||
|
|
||||||
ADD_IP_ALIASES=Yes
|
ADD_IP_ALIASES=Yes
|
||||||
|
|
||||||
@@ -191,6 +191,10 @@ AUTOMAKE=No
|
|||||||
|
|
||||||
WIDE_TC_MARKS=Yes
|
WIDE_TC_MARKS=Yes
|
||||||
|
|
||||||
|
TRACK_PROVIDERS=Yes
|
||||||
|
|
||||||
|
ZONE2ZONE=2
|
||||||
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
# P A C K E T D I S P O S I T I O N
|
# P A C K E T D I S P O S I T I O N
|
||||||
###############################################################################
|
###############################################################################
|
||||||
|
@@ -10,9 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#-----------------------------------------------------------------------------
|
#-----------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-zones"
|
# For information about entries in this file, type "man shorewall-zones"
|
||||||
#
|
|
||||||
# For more information, see http://www.shorewall.net/Documentation.htm#Zones
|
|
||||||
#
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
#ZONE TYPE OPTIONS IN OUT
|
#ZONE TYPE OPTIONS IN OUT
|
||||||
# OPTIONS OPTIONS
|
# OPTIONS OPTIONS
|
||||||
|
@@ -10,10 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-interfaces"
|
# For information about entries in this file, type "man shorewall-interfaces"
|
||||||
#
|
|
||||||
# For additional information, see
|
|
||||||
# http://shorewall.net/Documentation.htm#Interfaces
|
|
||||||
#
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
#ZONE INTERFACE BROADCAST OPTIONS
|
#ZONE INTERFACE BROADCAST OPTIONS
|
||||||
net eth0 detect tcpflags,dhcp,nosmurfs,routefilter,logmartians
|
net eth0 detect tcpflags,dhcp,nosmurfs,routefilter,logmartians
|
||||||
|
@@ -10,9 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-masq"
|
# For information about entries in this file, type "man shorewall-masq"
|
||||||
#
|
|
||||||
# For additional information, see http://shorewall.net/Documentation.htm#Masq
|
|
||||||
#
|
|
||||||
##############################################################################
|
##############################################################################
|
||||||
#INTERFACE SOURCE ADDRESS PROTO PORT(S) IPSEC MARK
|
#INTERFACE SOURCE ADDRESS PROTO PORT(S) IPSEC MARK
|
||||||
eth0 10.0.0.0/8,\
|
eth0 10.0.0.0/8,\
|
||||||
|
@@ -10,9 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-policy"
|
# For information about entries in this file, type "man shorewall-policy"
|
||||||
#
|
|
||||||
# See http://shorewall.net/Documentation.htm#Policy for additional information.
|
|
||||||
#
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
#SOURCE DEST POLICY LOG LEVEL LIMIT:BURST
|
#SOURCE DEST POLICY LOG LEVEL LIMIT:BURST
|
||||||
|
|
||||||
|
@@ -10,11 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-routestopped"
|
# For information about entries in this file, type "man shorewall-routestopped"
|
||||||
#
|
|
||||||
# See http://shorewall.net/Documentation.htm#Routestopped and
|
|
||||||
# http://shorewall.net/starting_and_stopping_shorewall.htm for additional
|
|
||||||
# information.
|
|
||||||
#
|
|
||||||
##############################################################################
|
##############################################################################
|
||||||
#INTERFACE HOST(S)
|
#INTERFACE HOST(S)
|
||||||
eth1 -
|
eth1 -
|
||||||
|
@@ -10,42 +10,39 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-rules"
|
# For information about entries in this file, type "man shorewall-rules"
|
||||||
#
|
|
||||||
# For additional information, see http://shorewall.net/Documentation.htm#Rules
|
|
||||||
#
|
|
||||||
#############################################################################################################
|
#############################################################################################################
|
||||||
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK
|
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK
|
||||||
# PORT PORT(S) DEST LIMIT GROUP
|
# PORT PORT(S) DEST LIMIT GROUP
|
||||||
#
|
#
|
||||||
# Accept DNS connections from the firewall to the Internet
|
# Accept DNS connections from the firewall to the Internet
|
||||||
#
|
#
|
||||||
DNS/ACCEPT $FW net
|
DNS(ACCEPT) $FW net
|
||||||
#
|
#
|
||||||
#
|
#
|
||||||
# Accept SSH connections from the local network to the firewall and DMZ
|
# Accept SSH connections from the local network to the firewall and DMZ
|
||||||
#
|
#
|
||||||
SSH/ACCEPT loc $FW
|
SSH(ACCEPT) loc $FW
|
||||||
SSH/ACCEPT loc dmz
|
SSH(ACCEPT) loc dmz
|
||||||
#
|
#
|
||||||
# DMZ DNS access to the Internet
|
# DMZ DNS access to the Internet
|
||||||
#
|
#
|
||||||
DNS/ACCEPT dmz net
|
DNS(ACCEPT) dmz net
|
||||||
|
|
||||||
|
|
||||||
# Drop Ping from the "bad" net zone.
|
# Drop Ping from the "bad" net zone.
|
||||||
|
|
||||||
Ping/DROP net $FW
|
Ping(DROP) net $FW
|
||||||
|
|
||||||
#
|
#
|
||||||
# Make ping work bi-directionally between the dmz, net, Firewall and local zone
|
# Make ping work bi-directionally between the dmz, net, Firewall and local zone
|
||||||
# (assumes that the loc-> net policy is ACCEPT).
|
# (assumes that the loc-> net policy is ACCEPT).
|
||||||
#
|
#
|
||||||
|
|
||||||
Ping/ACCEPT loc $FW
|
Ping(ACCEPT) loc $FW
|
||||||
Ping/ACCEPT dmz $FW
|
Ping(ACCEPT) dmz $FW
|
||||||
Ping/ACCEPT loc dmz
|
Ping(ACCEPT) loc dmz
|
||||||
Ping/ACCEPT dmz loc
|
Ping(ACCEPT) dmz loc
|
||||||
Ping/ACCEPT dmz net
|
Ping(ACCEPT) dmz net
|
||||||
|
|
||||||
ACCEPT $FW net icmp
|
ACCEPT $FW net icmp
|
||||||
ACCEPT $FW loc icmp
|
ACCEPT $FW loc icmp
|
||||||
@@ -54,5 +51,5 @@ ACCEPT $FW dmz icmp
|
|||||||
# Uncomment this if using Proxy ARP and static NAT and you want to allow ping from
|
# Uncomment this if using Proxy ARP and static NAT and you want to allow ping from
|
||||||
# the net zone to the dmz and loc
|
# the net zone to the dmz and loc
|
||||||
|
|
||||||
#Ping/ACCEPT net dmz
|
#Ping(ACCEPT) net dmz
|
||||||
#Ping/ACCEPT net loc
|
#Ping(ACCEPT) net loc
|
||||||
|
@@ -34,9 +34,9 @@ VERBOSITY=1
|
|||||||
|
|
||||||
LOGFILE=/var/log/messages
|
LOGFILE=/var/log/messages
|
||||||
|
|
||||||
STARTUP_LOG=
|
STARTUP_LOG=/var/log/shorewall-init.log
|
||||||
|
|
||||||
LOG_VERBOSITY=
|
LOG_VERBOSITY=2
|
||||||
|
|
||||||
LOGFORMAT="Shorewall:%s:%s:"
|
LOGFORMAT="Shorewall:%s:%s:"
|
||||||
|
|
||||||
@@ -191,6 +191,10 @@ AUTOMAKE=No
|
|||||||
|
|
||||||
WIDE_TC_MARKS=Yes
|
WIDE_TC_MARKS=Yes
|
||||||
|
|
||||||
|
TRACK_PROVIDERS=Yes
|
||||||
|
|
||||||
|
ZONE2ZONE=2
|
||||||
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
# P A C K E T D I S P O S I T I O N
|
# P A C K E T D I S P O S I T I O N
|
||||||
###############################################################################
|
###############################################################################
|
||||||
|
@@ -10,9 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-zones"
|
# For information about entries in this file, type "man shorewall-zones"
|
||||||
#
|
|
||||||
# For more information, see http://www.shorewall.net/Documentation.htm#Zones
|
|
||||||
#
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
#ZONE TYPE OPTIONS IN OUT
|
#ZONE TYPE OPTIONS IN OUT
|
||||||
# OPTIONS OPTIONS
|
# OPTIONS OPTIONS
|
||||||
|
@@ -10,10 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-interfaces"
|
# For information about entries in this file, type "man shorewall-interfaces"
|
||||||
#
|
|
||||||
# For additional information, see
|
|
||||||
# http://shorewall.net/Documentation.htm#Interfaces
|
|
||||||
#
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
#ZONE INTERFACE BROADCAST OPTIONS
|
#ZONE INTERFACE BROADCAST OPTIONS
|
||||||
net eth0 detect dhcp,tcpflags,nosmurfs,routefilter,logmartians
|
net eth0 detect dhcp,tcpflags,nosmurfs,routefilter,logmartians
|
||||||
|
@@ -10,9 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-masq"
|
# For information about entries in this file, type "man shorewall-masq"
|
||||||
#
|
|
||||||
# For additional information, see http://shorewall.net/Documentation.htm#Masq
|
|
||||||
#
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
#INTERFACE SOURCE ADDRESS PROTO PORT(S) IPSEC MARK
|
#INTERFACE SOURCE ADDRESS PROTO PORT(S) IPSEC MARK
|
||||||
eth0 10.0.0.0/8,\
|
eth0 10.0.0.0/8,\
|
||||||
|
@@ -10,9 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-policy"
|
# For information about entries in this file, type "man shorewall-policy"
|
||||||
#
|
|
||||||
# See http://shorewall.net/Documentation.htm#Policy for additional information.
|
|
||||||
#
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
#SOURCE DEST POLICY LOG LEVEL LIMIT:BURST
|
#SOURCE DEST POLICY LOG LEVEL LIMIT:BURST
|
||||||
|
|
||||||
|
@@ -10,11 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-routestopped"
|
# For information about entries in this file, type "man shorewall-routestopped"
|
||||||
#
|
|
||||||
# See http://shorewall.net/Documentation.htm#Routestopped and
|
|
||||||
# http://shorewall.net/starting_and_stopping_shorewall.htm for additional
|
|
||||||
# information.
|
|
||||||
#
|
|
||||||
##############################################################################
|
##############################################################################
|
||||||
#INTERFACE HOST(S) OPTIONS
|
#INTERFACE HOST(S) OPTIONS
|
||||||
eth1 -
|
eth1 -
|
||||||
|
@@ -10,30 +10,27 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-rules"
|
# For information about entries in this file, type "man shorewall-rules"
|
||||||
#
|
|
||||||
# For more information, see http://www.shorewall.net/Documentation.htm#Rules
|
|
||||||
#
|
|
||||||
#############################################################################################################
|
#############################################################################################################
|
||||||
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK
|
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK
|
||||||
# PORT PORT(S) DEST LIMIT GROUP
|
# PORT PORT(S) DEST LIMIT GROUP
|
||||||
#
|
#
|
||||||
# Accept DNS connections from the firewall to the network
|
# Accept DNS connections from the firewall to the network
|
||||||
#
|
#
|
||||||
DNS/ACCEPT $FW net
|
DNS(ACCEPT) $FW net
|
||||||
#
|
#
|
||||||
# Accept SSH connections from the local network for administration
|
# Accept SSH connections from the local network for administration
|
||||||
#
|
#
|
||||||
SSH/ACCEPT loc $FW
|
SSH(ACCEPT) loc $FW
|
||||||
#
|
#
|
||||||
# Allow Ping from the local network
|
# Allow Ping from the local network
|
||||||
#
|
#
|
||||||
Ping/ACCEPT loc $FW
|
Ping(ACCEPT) loc $FW
|
||||||
|
|
||||||
#
|
#
|
||||||
# Drop Ping from the "bad" net zone.. and prevent your log from being flooded..
|
# Drop Ping from the "bad" net zone.. and prevent your log from being flooded..
|
||||||
#
|
#
|
||||||
|
|
||||||
Ping/DROP net $FW
|
Ping(DROP) net $FW
|
||||||
|
|
||||||
ACCEPT $FW loc icmp
|
ACCEPT $FW loc icmp
|
||||||
ACCEPT $FW net icmp
|
ACCEPT $FW net icmp
|
||||||
|
@@ -41,9 +41,9 @@ SHOREWALL_COMPILER=
|
|||||||
|
|
||||||
LOGFILE=/var/log/messages
|
LOGFILE=/var/log/messages
|
||||||
|
|
||||||
STARTUP_LOG=
|
STARTUP_LOG=/var/log/shorewall-init.log
|
||||||
|
|
||||||
LOG_VERBOSITY=
|
LOG_VERBOSITY=2
|
||||||
|
|
||||||
LOGFORMAT="Shorewall:%s:%s:"
|
LOGFORMAT="Shorewall:%s:%s:"
|
||||||
|
|
||||||
@@ -198,6 +198,10 @@ AUTOMAKE=No
|
|||||||
|
|
||||||
WIDE_TC_MARKS=Yes
|
WIDE_TC_MARKS=Yes
|
||||||
|
|
||||||
|
TRACK_PROVIDERS=Yes
|
||||||
|
|
||||||
|
ZONE2ZONE=2
|
||||||
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
# P A C K E T D I S P O S I T I O N
|
# P A C K E T D I S P O S I T I O N
|
||||||
###############################################################################
|
###############################################################################
|
||||||
|
@@ -10,9 +10,6 @@
|
|||||||
# See the file README.txt for further details.
|
# See the file README.txt for further details.
|
||||||
#------------------------------------------------------------------------------
|
#------------------------------------------------------------------------------
|
||||||
# For information about entries in this file, type "man shorewall-zones"
|
# For information about entries in this file, type "man shorewall-zones"
|
||||||
#
|
|
||||||
# For more information, see http://www.shorewall.net/Documentation.htm#Zones
|
|
||||||
#
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
#ZONE TYPE OPTIONS IN OUT
|
#ZONE TYPE OPTIONS IN OUT
|
||||||
# OPTIONS OPTIONS
|
# OPTIONS OPTIONS
|
||||||
|
@@ -16,10 +16,9 @@
|
|||||||
|
|
||||||
# Drop Ping from the "bad" net zone.. and prevent your log from being flooded..
|
# Drop Ping from the "bad" net zone.. and prevent your log from being flooded..
|
||||||
|
|
||||||
Ping/DROP net $FW
|
Ping(DROP) net $FW
|
||||||
|
|
||||||
# Permit all ICMP traffic FROM the firewall TO the net zone
|
# Permit all ICMP traffic FROM the firewall TO the net zone
|
||||||
|
|
||||||
ACCEPT $FW net ipv6-icmp
|
ACCEPT $FW net ipv6-icmp
|
||||||
|
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -32,9 +32,9 @@ VERBOSITY=1
|
|||||||
|
|
||||||
LOGFILE=/var/log/messages
|
LOGFILE=/var/log/messages
|
||||||
|
|
||||||
STARTUP_LOG=
|
STARTUP_LOG=/var/log/shorewall6-init.log
|
||||||
|
|
||||||
LOG_VERBOSITY=
|
LOG_VERBOSITY=2
|
||||||
|
|
||||||
LOGFORMAT="Shorewall:%s:%s:"
|
LOGFORMAT="Shorewall:%s:%s:"
|
||||||
|
|
||||||
@@ -139,6 +139,10 @@ AUTOMAKE=No
|
|||||||
|
|
||||||
WIDE_TC_MARKS=Yes
|
WIDE_TC_MARKS=Yes
|
||||||
|
|
||||||
|
TRACK_PROVIDERS=Yes
|
||||||
|
|
||||||
|
ZONE2ZONE=2
|
||||||
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
# P A C K E T D I S P O S I T I O N
|
# P A C K E T D I S P O S I T I O N
|
||||||
###############################################################################
|
###############################################################################
|
||||||
|
@@ -16,33 +16,33 @@
|
|||||||
#
|
#
|
||||||
# Accept DNS connections from the firewall to the Internet
|
# Accept DNS connections from the firewall to the Internet
|
||||||
#
|
#
|
||||||
DNS/ACCEPT $FW net
|
DNS(ACCEPT) $FW net
|
||||||
#
|
#
|
||||||
#
|
#
|
||||||
# Accept SSH connections from the local network to the firewall and DMZ
|
# Accept SSH connections from the local network to the firewall and DMZ
|
||||||
#
|
#
|
||||||
SSH/ACCEPT loc $FW
|
SSH(ACCEPT) loc $FW
|
||||||
SSH/ACCEPT loc dmz
|
SSH(ACCEPT) loc dmz
|
||||||
#
|
#
|
||||||
# DMZ DNS access to the Internet
|
# DMZ DNS access to the Internet
|
||||||
#
|
#
|
||||||
DNS/ACCEPT dmz net
|
DNS(ACCEPT) dmz net
|
||||||
|
|
||||||
|
|
||||||
# Drop Ping from the "bad" net zone.
|
# Drop Ping from the "bad" net zone.
|
||||||
|
|
||||||
Ping/DROP net $FW
|
Ping(DROP) net $FW
|
||||||
|
|
||||||
#
|
#
|
||||||
# Make ping work bi-directionally between the dmz, net, Firewall and local zone
|
# Make ping work bi-directionally between the dmz, net, Firewall and local zone
|
||||||
# (assumes that the loc-> net policy is ACCEPT).
|
# (assumes that the loc-> net policy is ACCEPT).
|
||||||
#
|
#
|
||||||
|
|
||||||
Ping/ACCEPT loc $FW
|
Ping(ACCEPT) loc $FW
|
||||||
Ping/ACCEPT dmz $FW
|
Ping(ACCEPT) dmz $FW
|
||||||
Ping/ACCEPT loc dmz
|
Ping(ACCEPT) loc dmz
|
||||||
Ping/ACCEPT dmz loc
|
Ping(ACCEPT) dmz loc
|
||||||
Ping/ACCEPT dmz net
|
Ping(ACCEPT) dmz net
|
||||||
|
|
||||||
ACCEPT $FW net ipv6-icmp
|
ACCEPT $FW net ipv6-icmp
|
||||||
ACCEPT $FW loc ipv6-icmp
|
ACCEPT $FW loc ipv6-icmp
|
||||||
@@ -51,6 +51,6 @@ ACCEPT $FW dmz ipv6-icmp
|
|||||||
# Uncomment this if using Proxy ARP and static NAT and you want to allow ping from
|
# Uncomment this if using Proxy ARP and static NAT and you want to allow ping from
|
||||||
# the net zone to the dmz and loc
|
# the net zone to the dmz and loc
|
||||||
|
|
||||||
#Ping/ACCEPT net dmz
|
#Ping(ACCEPT) net dmz
|
||||||
#Ping/ACCEPT net loc
|
#Ping(ACCEPT) net loc
|
||||||
|
|
||||||
|
@@ -32,9 +32,9 @@ VERBOSITY=1
|
|||||||
|
|
||||||
LOGFILE=/var/log/messages
|
LOGFILE=/var/log/messages
|
||||||
|
|
||||||
STARTUP_LOG=
|
STARTUP_LOG=/var/log/shorewall6-init.log
|
||||||
|
|
||||||
LOG_VERBOSITY=
|
LOG_VERBOSITY=2
|
||||||
|
|
||||||
LOGFORMAT="Shorewall:%s:%s:"
|
LOGFORMAT="Shorewall:%s:%s:"
|
||||||
|
|
||||||
@@ -139,6 +139,10 @@ AUTOMAKE=No
|
|||||||
|
|
||||||
WIDE_TC_MARKS=Yes
|
WIDE_TC_MARKS=Yes
|
||||||
|
|
||||||
|
TRACK_PROVIDERS=Yes
|
||||||
|
|
||||||
|
ZONE2ZONE=2
|
||||||
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
# P A C K E T D I S P O S I T I O N
|
# P A C K E T D I S P O S I T I O N
|
||||||
###############################################################################
|
###############################################################################
|
||||||
|
@@ -16,21 +16,21 @@
|
|||||||
#
|
#
|
||||||
# Accept DNS connections from the firewall to the network
|
# Accept DNS connections from the firewall to the network
|
||||||
#
|
#
|
||||||
DNS/ACCEPT $FW net
|
DNS(ACCEPT) $FW net
|
||||||
#
|
#
|
||||||
# Accept SSH connections from the local network for administration
|
# Accept SSH connections from the local network for administration
|
||||||
#
|
#
|
||||||
SSH/ACCEPT loc $FW
|
SSH(ACCEPT) loc $FW
|
||||||
#
|
#
|
||||||
# Allow Ping from the local network
|
# Allow Ping from the local network
|
||||||
#
|
#
|
||||||
Ping/ACCEPT loc $FW
|
Ping(ACCEPT) loc $FW
|
||||||
|
|
||||||
#
|
#
|
||||||
# Drop Ping from the "bad" net zone.. and prevent your log from being flooded..
|
# Drop Ping from the "bad" net zone.. and prevent your log from being flooded..
|
||||||
#
|
#
|
||||||
|
|
||||||
Ping/DROP net $FW
|
Ping(DROP) net $FW
|
||||||
|
|
||||||
ACCEPT $FW loc ipv6-icmp
|
ACCEPT $FW loc ipv6-icmp
|
||||||
ACCEPT $FW net ipv6-icmp
|
ACCEPT $FW net ipv6-icmp
|
||||||
|
@@ -32,9 +32,9 @@ VERBOSITY=1
|
|||||||
|
|
||||||
LOGFILE=/var/log/messages
|
LOGFILE=/var/log/messages
|
||||||
|
|
||||||
STARTUP_LOG=
|
STARTUP_LOG=/var/log/shorewall6-init.log
|
||||||
|
|
||||||
LOG_VERBOSITY=
|
LOG_VERBOSITY=2
|
||||||
|
|
||||||
LOGFORMAT="Shorewall:%s:%s:"
|
LOGFORMAT="Shorewall:%s:%s:"
|
||||||
|
|
||||||
@@ -139,6 +139,10 @@ AUTOMAKE=No
|
|||||||
|
|
||||||
WIDE_TC_MARKS=Yes
|
WIDE_TC_MARKS=Yes
|
||||||
|
|
||||||
|
TRACK_PROVIDERS=Yes
|
||||||
|
|
||||||
|
ZONE2ZONE=2
|
||||||
|
|
||||||
###############################################################################
|
###############################################################################
|
||||||
# P A C K E T D I S P O S I T I O N
|
# P A C K E T D I S P O S I T I O N
|
||||||
###############################################################################
|
###############################################################################
|
||||||
|
@@ -21,4 +21,9 @@ startup=0
|
|||||||
|
|
||||||
OPTIONS=""
|
OPTIONS=""
|
||||||
|
|
||||||
|
#
|
||||||
|
# Init Log -- if /dev/null, use the STARTUP_LOG defined in shorewall.conf
|
||||||
|
#
|
||||||
|
INITLOG=/dev/null
|
||||||
|
|
||||||
# EOF
|
# EOF
|
||||||
|
@@ -28,7 +28,7 @@
|
|||||||
# shown below. Simply run this script to revert to your prior version of
|
# shown below. Simply run this script to revert to your prior version of
|
||||||
# Shoreline Firewall.
|
# Shoreline Firewall.
|
||||||
|
|
||||||
VERSION=4.4.0-RC2
|
VERSION=4.4.4
|
||||||
|
|
||||||
usage() # $1 = exit status
|
usage() # $1 = exit status
|
||||||
{
|
{
|
||||||
|
@@ -15,9 +15,7 @@
|
|||||||
|
|
||||||
SRWL=/sbin/shorewall-lite
|
SRWL=/sbin/shorewall-lite
|
||||||
SRWL_OPTS="-tvv"
|
SRWL_OPTS="-tvv"
|
||||||
# Note, set INITLOG to /dev/null if you do not want to
|
test -n ${INITLOG:=/var/log/shorewall-lite-init.log}
|
||||||
# keep logs of the firewall (not recommended)
|
|
||||||
INITLOG=/var/log/shorewall-lite-init.log
|
|
||||||
|
|
||||||
[ "$INITLOG" eq "/dev/null" && SHOREWALL_INIT_SCRIPT=1 || SHOREWALL_INIT_SCRIPT=0
|
[ "$INITLOG" eq "/dev/null" && SHOREWALL_INIT_SCRIPT=1 || SHOREWALL_INIT_SCRIPT=0
|
||||||
|
|
||||||
@@ -25,7 +23,7 @@ export SHOREWALL_INIT_SCRIPT
|
|||||||
|
|
||||||
test -x $SRWL || exit 0
|
test -x $SRWL || exit 0
|
||||||
test -x $WAIT_FOR_IFUP || exit 0
|
test -x $WAIT_FOR_IFUP || exit 0
|
||||||
test -n $INITLOG || {
|
test -n "$INITLOG" || {
|
||||||
echo "INITLOG cannot be empty, please configure $0" ;
|
echo "INITLOG cannot be empty, please configure $0" ;
|
||||||
exit 1;
|
exit 1;
|
||||||
}
|
}
|
||||||
|
@@ -22,7 +22,7 @@
|
|||||||
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
#
|
#
|
||||||
|
|
||||||
VERSION=4.4.0-RC2
|
VERSION=4.4.4
|
||||||
|
|
||||||
usage() # $1 = exit status
|
usage() # $1 = exit status
|
||||||
{
|
{
|
||||||
@@ -220,6 +220,11 @@ mkdir -p ${PREFIX}/var/lib/shorewall-lite
|
|||||||
chmod 755 ${PREFIX}/etc/shorewall-lite
|
chmod 755 ${PREFIX}/etc/shorewall-lite
|
||||||
chmod 755 ${PREFIX}/usr/share/shorewall-lite
|
chmod 755 ${PREFIX}/usr/share/shorewall-lite
|
||||||
|
|
||||||
|
if [ -n "$PREFIX" ]; then
|
||||||
|
mkdir -p ${PREFIX}/etc/logrotate.d
|
||||||
|
chmod 755 ${PREFIX}/etc/logrotate.d
|
||||||
|
fi
|
||||||
|
|
||||||
#
|
#
|
||||||
# Install the config file
|
# Install the config file
|
||||||
#
|
#
|
||||||
@@ -304,6 +309,12 @@ cd ..
|
|||||||
|
|
||||||
echo "Man Pages Installed"
|
echo "Man Pages Installed"
|
||||||
|
|
||||||
|
if [ -d ${PREFIX}/etc/logrotate.d ]; then
|
||||||
|
run_install $OWNERSHIP -m 0644 logrotate ${PREFIX}/etc/logrotate.d/shorewall-lite
|
||||||
|
echo "Logrotate file installed as ${PREFIX}/etc/logrotate.d/shorewall-lite"
|
||||||
|
fi
|
||||||
|
|
||||||
|
|
||||||
#
|
#
|
||||||
# Create the version file
|
# Create the version file
|
||||||
#
|
#
|
||||||
|
5
Shorewall-lite/logrotate
Normal file
5
Shorewall-lite/logrotate
Normal file
@@ -0,0 +1,5 @@
|
|||||||
|
/var/log/shorewall-init.log {
|
||||||
|
missingok
|
||||||
|
notifempty
|
||||||
|
create 0600 root root
|
||||||
|
}
|
@@ -1,6 +1,6 @@
|
|||||||
%define name shorewall-lite
|
%define name shorewall-lite
|
||||||
%define version 4.4.0
|
%define version 4.4.4
|
||||||
%define release 0RC2
|
%define release 0base
|
||||||
|
|
||||||
Summary: Shoreline Firewall Lite is an iptables-based firewall for Linux systems.
|
Summary: Shoreline Firewall Lite is an iptables-based firewall for Linux systems.
|
||||||
Name: %{name}
|
Name: %{name}
|
||||||
@@ -79,6 +79,8 @@ fi
|
|||||||
%attr(0755,root,root) %dir /usr/share/shorewall-lite
|
%attr(0755,root,root) %dir /usr/share/shorewall-lite
|
||||||
%attr(0700,root,root) %dir /var/lib/shorewall-lite
|
%attr(0700,root,root) %dir /var/lib/shorewall-lite
|
||||||
|
|
||||||
|
%attr(0644,root,root) /etc/logrotate.d/shorewall-lite
|
||||||
|
|
||||||
%attr(0755,root,root) /sbin/shorewall-lite
|
%attr(0755,root,root) /sbin/shorewall-lite
|
||||||
|
|
||||||
%attr(0644,root,root) /usr/share/shorewall-lite/version
|
%attr(0644,root,root) /usr/share/shorewall-lite/version
|
||||||
@@ -98,6 +100,22 @@ fi
|
|||||||
%doc COPYING changelog.txt releasenotes.txt
|
%doc COPYING changelog.txt releasenotes.txt
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
|
* Fri Nov 13 2009 Tom Eastep tom@shorewall.net
|
||||||
|
- Updated to 4.4.4-0base
|
||||||
|
* Fri Nov 13 2009 Tom Eastep tom@shorewall.net
|
||||||
|
- Updated to 4.4.4-0Beta2
|
||||||
|
* Wed Nov 11 2009 Tom Eastep tom@shorewall.net
|
||||||
|
- Updated to 4.4.4-0Beta1
|
||||||
|
* Tue Nov 03 2009 Tom Eastep tom@shorewall.net
|
||||||
|
- Updated to 4.4.3-0base
|
||||||
|
* Sun Sep 06 2009 Tom Eastep tom@shorewall.net
|
||||||
|
- Updated to 4.4.2-0base
|
||||||
|
* Fri Sep 04 2009 Tom Eastep tom@shorewall.net
|
||||||
|
- Updated to 4.4.2-0base
|
||||||
|
* Fri Aug 14 2009 Tom Eastep tom@shorewall.net
|
||||||
|
- Updated to 4.4.1-0base
|
||||||
|
* Mon Aug 03 2009 Tom Eastep tom@shorewall.net
|
||||||
|
- Updated to 4.4.0-0base
|
||||||
* Tue Jul 28 2009 Tom Eastep tom@shorewall.net
|
* Tue Jul 28 2009 Tom Eastep tom@shorewall.net
|
||||||
- Updated to 4.4.0-0RC2
|
- Updated to 4.4.0-0RC2
|
||||||
* Sun Jul 12 2009 Tom Eastep tom@shorewall.net
|
* Sun Jul 12 2009 Tom Eastep tom@shorewall.net
|
||||||
|
@@ -26,7 +26,7 @@
|
|||||||
# You may only use this script to uninstall the version
|
# You may only use this script to uninstall the version
|
||||||
# shown below. Simply run this script to remove Shorewall Firewall
|
# shown below. Simply run this script to remove Shorewall Firewall
|
||||||
|
|
||||||
VERSION=4.4.0-RC2
|
VERSION=4.4.4
|
||||||
|
|
||||||
usage() # $1 = exit status
|
usage() # $1 = exit status
|
||||||
{
|
{
|
||||||
|
@@ -13,4 +13,3 @@ COMMENT Needed ICMP types
|
|||||||
|
|
||||||
ACCEPT - - icmp fragmentation-needed
|
ACCEPT - - icmp fragmentation-needed
|
||||||
ACCEPT - - icmp time-exceeded
|
ACCEPT - - icmp time-exceeded
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -18,4 +18,3 @@ PARAM - - udp 10080
|
|||||||
# systems which need to pass AMANDA traffic through netfilter.
|
# systems which need to pass AMANDA traffic through netfilter.
|
||||||
#PARAM - - tcp 50000:50100
|
#PARAM - - tcp 50000:50100
|
||||||
#
|
#
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 113
|
PARAM - - tcp 113
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 179 # BGP4
|
PARAM - - tcp 179 # BGP4
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -16,4 +16,3 @@ PARAM - - tcp 6881:6889
|
|||||||
#
|
#
|
||||||
PARAM - - udp 6881
|
PARAM - - udp 6881
|
||||||
#
|
#
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -14,4 +14,3 @@ PARAM - - tcp 6881:6999
|
|||||||
#
|
#
|
||||||
PARAM - - udp 6881
|
PARAM - - udp 6881
|
||||||
#
|
#
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 2401
|
PARAM - - tcp 2401
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -11,4 +11,3 @@
|
|||||||
PARAM - - tcp 1494 # ICA
|
PARAM - - tcp 1494 # ICA
|
||||||
PARAM - - udp 1604 # ICA Browser
|
PARAM - - udp 1604 # ICA Browser
|
||||||
PARAM - - tcp 2598 # CGP Session Reliabilty
|
PARAM - - tcp 2598 # CGP Session Reliabilty
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -11,4 +11,3 @@
|
|||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 3689
|
PARAM - - tcp 3689
|
||||||
PARAM - - udp 3689
|
PARAM - - udp 3689
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 6277
|
PARAM - - tcp 6277
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - udp 53
|
PARAM - - udp 53
|
||||||
PARAM - - tcp 53
|
PARAM - - tcp 53
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 3632
|
PARAM - - tcp 3632
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -50,4 +50,3 @@ dropNotSyn
|
|||||||
# the log.
|
# the log.
|
||||||
#
|
#
|
||||||
DROP - - udp - 53
|
DROP - - udp - 53
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -12,4 +12,3 @@
|
|||||||
COMMENT Late DNS Replies
|
COMMENT Late DNS Replies
|
||||||
|
|
||||||
DROP - - udp - 53
|
DROP - - udp - 53
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -12,4 +12,3 @@
|
|||||||
COMMENT UPnP
|
COMMENT UPnP
|
||||||
|
|
||||||
DROP - - udp 1900
|
DROP - - udp 1900
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -32,4 +32,3 @@
|
|||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 4662
|
PARAM - - tcp 4662
|
||||||
PARAM - - udp 4665
|
PARAM - - udp 4665
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 21
|
PARAM - - tcp 21
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 79
|
PARAM - - tcp 79
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -12,4 +12,3 @@ PARAM - - tcp 2086
|
|||||||
PARAM - - udp 2086
|
PARAM - - udp 2086
|
||||||
PARAM - - tcp 1080
|
PARAM - - tcp 1080
|
||||||
PARAM - - udp 1080
|
PARAM - - udp 1080
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -11,4 +11,3 @@
|
|||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - 47 # GRE
|
PARAM - - 47 # GRE
|
||||||
PARAM DEST SOURCE 47 # GRE
|
PARAM DEST SOURCE 47 # GRE
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 9418
|
PARAM - - tcp 9418
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 6346
|
PARAM - - tcp 6346
|
||||||
PARAM - - udp 6346
|
PARAM - - udp 6346
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 80
|
PARAM - - tcp 80
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 443
|
PARAM - - tcp 443
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 5190
|
PARAM - - tcp 5190
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 143
|
PARAM - - tcp 143
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 993
|
PARAM - - tcp 993
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - 94 # IPIP
|
PARAM - - 94 # IPIP
|
||||||
PARAM DEST SOURCE 94 # IPIP
|
PARAM DEST SOURCE 94 # IPIP
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 631
|
PARAM - - tcp 631
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - udp 631
|
PARAM - - udp 631
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -27,4 +27,3 @@
|
|||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM SOURCE DEST tcp 631
|
PARAM SOURCE DEST tcp 631
|
||||||
PARAM DEST SOURCE udp 631
|
PARAM DEST SOURCE udp 631
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -12,4 +12,3 @@ PARAM - - udp 500 500 # IKE
|
|||||||
PARAM - - 50 # ESP
|
PARAM - - 50 # ESP
|
||||||
PARAM DEST SOURCE udp 500 500 # IKE
|
PARAM DEST SOURCE udp 500 500 # IKE
|
||||||
PARAM DEST SOURCE 50 # ESP
|
PARAM DEST SOURCE 50 # ESP
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -13,4 +13,3 @@ PARAM - - udp 500 500 # IKE
|
|||||||
PARAM - - 51 # AH
|
PARAM - - 51 # AH
|
||||||
PARAM DEST SOURCE udp 500 500 # IKE
|
PARAM DEST SOURCE udp 500 500 # IKE
|
||||||
PARAM DEST SOURCE 51 # AH
|
PARAM DEST SOURCE 51 # AH
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -14,4 +14,3 @@ PARAM - - 50 # ESP
|
|||||||
PARAM DEST SOURCE udp 500 # IKE
|
PARAM DEST SOURCE udp 500 # IKE
|
||||||
PARAM DEST SOURCE udp 4500 # NAT-T
|
PARAM DEST SOURCE udp 4500 # NAT-T
|
||||||
PARAM DEST SOURCE 50 # ESP
|
PARAM DEST SOURCE 50 # ESP
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 6667
|
PARAM - - tcp 6667
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -15,4 +15,3 @@ PARAM - - tcp 6544 # HTTP port
|
|||||||
PARAM - - tcp 6543 # InfoService port
|
PARAM - - tcp 6543 # InfoService port
|
||||||
HTTPS/PARAM
|
HTTPS/PARAM
|
||||||
SSH/PARAM
|
SSH/PARAM
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#TARGET SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#TARGET SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 5222
|
PARAM - - tcp 5222
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#TARGET SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#TARGET SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 5223
|
PARAM - - tcp 5223
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#TARGET SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#TARGET SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 5269
|
PARAM - - tcp 5269
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 9100
|
PARAM - - tcp 9100
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -11,4 +11,3 @@
|
|||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - udp 1701 # L2TP
|
PARAM - - udp 1701 # L2TP
|
||||||
PARAM DEST SOURCE udp 1701 # L2TP
|
PARAM DEST SOURCE udp 1701 # L2TP
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -14,4 +14,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 389
|
PARAM - - tcp 389
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -14,4 +14,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 636
|
PARAM - - tcp 636
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 3306
|
PARAM - - tcp 3306
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 119
|
PARAM - - tcp 119
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 563
|
PARAM - - tcp 563
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - udp 123
|
PARAM - - udp 123
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - udp 123
|
PARAM - - udp 123
|
||||||
PARAM DEST SOURCE udp 123
|
PARAM DEST SOURCE udp 123
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -15,4 +15,3 @@
|
|||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - udp 123
|
PARAM - - udp 123
|
||||||
PARAM - - udp 1024: 123
|
PARAM - - udp 1024: 123
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ ORIGINAL
|
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ ORIGINAL
|
||||||
# PORT(S) PORT(S) DEST LIMIT GROUP DEST
|
# PORT(S) PORT(S) DEST LIMIT GROUP DEST
|
||||||
PARAM - - 89 - # OSPF
|
PARAM - - 89 - # OSPF
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - udp 1194
|
PARAM - - udp 1194
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - udp 5632
|
PARAM - - udp 5632
|
||||||
PARAM - - tcp 5631
|
PARAM - - tcp 5631
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 110
|
PARAM - - tcp 110
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,4 +10,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 995 # Secure POP3
|
PARAM - - tcp 995 # Secure POP3
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -11,4 +11,3 @@
|
|||||||
PARAM - - 47
|
PARAM - - 47
|
||||||
PARAM DEST SOURCE 47
|
PARAM DEST SOURCE 47
|
||||||
PARAM - - tcp 1723
|
PARAM - - tcp 1723
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - icmp 8
|
PARAM - - icmp 8
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 5432
|
PARAM - - tcp 5432
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 515
|
PARAM - - tcp 515
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 3389
|
PARAM - - tcp 3389
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -10,5 +10,4 @@
|
|||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - udp 520
|
PARAM - - udp 520
|
||||||
PARAM DEST SOURCE udp 520
|
PARAM DEST SOURCE udp 520
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 953
|
PARAM - - tcp 953
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
ACCEPT - - tcp 2703
|
ACCEPT - - tcp 2703
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -13,4 +13,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 37
|
PARAM - - tcp 37
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -51,4 +51,3 @@ dropNotSyn
|
|||||||
# the log.
|
# the log.
|
||||||
#
|
#
|
||||||
DROP - - udp - 53
|
DROP - - udp - 53
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -11,4 +11,3 @@ FORMAT 2
|
|||||||
PARAM SOURCE:10.0.0.0/8,172.16.0.0/12,192.168.0.0/16 \
|
PARAM SOURCE:10.0.0.0/8,172.16.0.0/12,192.168.0.0/16 \
|
||||||
DEST - - - - - -
|
DEST - - - - - -
|
||||||
PARAM SOURCE DEST - - - 10.0.0.0/8,172.16.0.0/12,192.168.0.0/16
|
PARAM SOURCE DEST - - - 10.0.0.0/8,172.16.0.0/12,192.168.0.0/16
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -9,4 +9,3 @@
|
|||||||
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/
|
||||||
# PORT(S) PORT(S) LIMIT GROUP
|
# PORT(S) PORT(S) LIMIT GROUP
|
||||||
PARAM - - tcp 873
|
PARAM - - tcp 873
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -20,4 +20,3 @@ PARAM - - tcp 6566
|
|||||||
#PARAM - - tcp 32768:61000
|
#PARAM - - tcp 32768:61000
|
||||||
# This is generic rule for any os running saned.
|
# This is generic rule for any os running saned.
|
||||||
#PARAM - - tcp 1024:
|
#PARAM - - tcp 1024:
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
@@ -16,4 +16,3 @@ PARAM - - udp 135,445
|
|||||||
PARAM - - udp 137:139
|
PARAM - - udp 137:139
|
||||||
PARAM - - udp 1024: 137
|
PARAM - - udp 1024: 137
|
||||||
PARAM - - tcp 135,139,445
|
PARAM - - tcp 135,139,445
|
||||||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|
|
||||||
|
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user