X-Git-Url: https://git.distorted.org.uk/~mdw/firewall/blobdiff_plain/31c0a1076869a8595716b0ea2666f5cc8123379e..4aa2b49cc41cd34e1fc54858ca26c190d5b925cc:/local.m4 diff --git a/local.m4 b/local.m4 index 78e63d4..785a78b 100644 --- a/local.m4 +++ b/local.m4 @@ -90,7 +90,7 @@ m4_divert(-1) ## top nibble of the network number classifies the network, as follows. ## ## 8xxx Untrusted -## 6xxx Virtual +## 6xxx Virtual, safe ## 4xxx Safe ## 0xxx Unsafe, trusted ## @@ -143,7 +143,6 @@ defnet househub virtual via housebdry dmz unsafe safe untrusted defnet housebdry virtual via househub hub - noxit dmz ## House hosts. defhost radius @@ -183,6 +182,10 @@ defhost ibanez defhost orange iface wlan0 untrusted iface vpn-radius unsafe +defhost groove + iface eth0 unsafe + iface wlan0 untrusted + iface vpn-radius unsafe defhost gibson hosttype client @@ -199,7 +202,6 @@ defnet colohub virtual via colobdry jump colo defnet colobdry virtual via colohub hub - noxit jump defnet iodine untrusted addr 172.29.198.128/28 via colohub @@ -222,6 +224,8 @@ defhost telecaster defhost stratocaster iface eth0 jump colo iface eth1 jump colo +defhost jaguar + iface eth0 jump defhost jazz hosttype router iface eth0 jump colo vpn @@ -241,9 +245,11 @@ defnet sgo noloop defnet vpn safe addr 172.29.199.128/27 2001:ba8:1d9:6000::/64 via househub colohub - host crybaby 1 - host terror 2 - host orange 3 + host crybaby 1 ::1:1 + host terror 2 ::2:1 + host orange 3 ::3:1 + host haze 4 ::4:1 + host groove 5 ::5:1 defnet anycast trusted addr 172.29.199.224/27 2001:ba8:1d9:0::/64 via dmz unsafe safe untrusted jump colo vpn @@ -265,6 +271,14 @@ defhost mango m4_divert(80)m4_dnl ###-------------------------------------------------------------------------- +### Connection tracking helper modules. + +for i in ftp; do + modprobe nf_conntrack_$i +done + +m4_divert(80)m4_dnl +###-------------------------------------------------------------------------- ### Special forwarding exemptions. case $forward in