~mdw
/
firewall
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
fender: New host, with basic firewall.
[firewall]
/
ibanez.m4
diff --git
a/ibanez.m4
b/ibanez.m4
index
5fc1ecd
..
2ec2c1c
100644
(file)
--- a/
ibanez.m4
+++ b/
ibanez.m4
@@
-27,17
+27,23
@@
## This host isn't a router.
setconf(forward, 0)
## This host isn't a router.
setconf(forward, 0)
+## This host is involved in a routing asymmetry.
+setconf(rp_filter, 0)
+setconf(log_martians, 0)
+
###--------------------------------------------------------------------------
### Network interfaces.
m4_divert(44)m4_dnl
## Interface definitions.
###--------------------------------------------------------------------------
### Network interfaces.
m4_divert(44)m4_dnl
## Interface definitions.
-if_untrusted=br0
-if_trusted=br0
-if_vpn=br0
-if_iodine=br0
-if_its_mz=br0
-if_its_pi=br0
+if_dmz=br-dmz
+if_trusted=br-unsafe
+if_safe=$if_dmz,$if_trusted
+if_untrusted=$if_dmz,$if_trusted
+if_vpn=$if_dmz,$if_trusted
+if_iodine=$if_dmz,$if_trusted
+if_its_mz=$if_dmz,$if_trusted
+if_its_pi=$if_dmz,$if_trusted
m4_divert(-1)
###--------------------------------------------------------------------------
m4_divert(-1)
###--------------------------------------------------------------------------
@@
-46,7
+52,11
@@
m4_divert(-1)
m4_divert(82)m4_dnl
## Externally visible services.
allowservices inbound tcp \
m4_divert(82)m4_dnl
## Externally visible services.
allowservices inbound tcp \
- ssh
+ ssh \
+ ident
+
+## We have to provide NTP service. The guests sync to our clock.
+ntpclient inbound $ntp_servers
m4_divert(-1)
###----- That's all, folks --------------------------------------------------
m4_divert(-1)
###----- That's all, folks --------------------------------------------------