X-Git-Url: https://git.distorted.org.uk/~mdw/firewall/blobdiff_plain/deee94301a9892b3568cd134756ef73e825bf148..a188f54944e56c7588f7ebbabbef3cee19686575:/vampire.m4 diff --git a/vampire.m4 b/vampire.m4 index 224374a..f21009c 100644 --- a/vampire.m4 +++ b/vampire.m4 @@ -1,4 +1,4 @@ -### -*-m4-*- +### -*-sh-*- ### ### Firewall configuration for vampire ### @@ -22,16 +22,25 @@ ### Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. ###-------------------------------------------------------------------------- +### Config settings. + +## This router is involved in a routing asymmetry. +setconf(rp_filter, 0) +setconf(log_martians, 0) + +###-------------------------------------------------------------------------- ### Network interfaces. m4_divert(44)m4_dnl ## Interface definitions. -if_untrusted=eth0.1 -if_trusted=eth0.0 +if_dmz=eth0.0 +if_trusted=eth0.1 +if_safe=$if_dmz,$if_trusted +if_untrusted=eth0.3 if_vpn=vpn-+ if_iodine=dns+ -if_its_mz=eth0.0 -if_its_pi=eth0.0 +if_its_mz=$if_dmz,$if_trusted +if_its_pi=$if_dmz,$if_trusted m4_divert(-1) ###-------------------------------------------------------------------------- @@ -43,10 +52,11 @@ allowservices inbound tcp \ finger ident \ dns iodine \ ssh \ - smtp \ + smtp submission \ gnutella_svc \ ftp ftp_data \ rsync \ + imaps \ disorder mpd \ http https squid \ git \ @@ -85,7 +95,7 @@ run iptables -A OUTPUT -m multiport \ ## Other interesting things. dnsresolver inbound -ntpclient inbound 158.152.1.76 158.152.1.204 194.159.253.2 +ntpclient inbound $ntp_servers m4_divert(-1) ###----- That's all, folks --------------------------------------------------