X-Git-Url: https://git.distorted.org.uk/~mdw/firewall/blobdiff_plain/42e91fdf0e690e2e3869b597a1d50f8f6cb4c5f9..429f4314d0d1be69f7500cf7f97671595804fdd0:/vampire.m4 diff --git a/vampire.m4 b/vampire.m4 index 18365be..f6f5d46 100644 --- a/vampire.m4 +++ b/vampire.m4 @@ -1,4 +1,4 @@ -### -*-m4-*- +### -*-sh-*- ### ### Firewall configuration for vampire ### @@ -43,12 +43,13 @@ allowservices inbound tcp \ finger ident \ dns iodine \ ssh \ - smtp \ + smtp submission \ gnutella_svc \ ftp ftp_data \ rsync \ + imaps \ disorder mpd \ - http https \ + http https squid \ git \ tor_public tor_directory i2p allowservices inbound udp \ @@ -79,18 +80,13 @@ run iptables -A inbound -j ACCEPT \ -s 172.29.198.2 \ -p udp --destination-port $port_syslog -## Provide a web cache to local untrusted hosts. -run iptables -A inbound -j ACCEPT \ - -s 172.29.198.0/24 \ - -p tcp --destination-port $port_squid - ## Watch outgoing Tor usage. run iptables -A OUTPUT -m multiport \ -p tcp --source-ports $port_tor_public,$port_tor_directory ## Other interesting things. dnsresolver inbound -ntpclient inbound 158.152.1.76 158.152.1.204 194.159.253.2 +ntpclient inbound $ntp_servers m4_divert(-1) ###----- That's all, folks --------------------------------------------------