X-Git-Url: https://git.distorted.org.uk/~mdw/firewall/blobdiff_plain/f2cfcfa875be6c08dbcc21fe31ca8fed89224bd3..beb4f0eeafb386d83f2593fec489f4291583e08b:/vampire.m4 diff --git a/vampire.m4 b/vampire.m4 index 224374a..6ddbbf5 100644 --- a/vampire.m4 +++ b/vampire.m4 @@ -1,4 +1,4 @@ -### -*-m4-*- +### -*-sh-*- ### ### Firewall configuration for vampire ### @@ -22,31 +22,26 @@ ### Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. ###-------------------------------------------------------------------------- -### Network interfaces. +### Config settings. -m4_divert(44)m4_dnl -## Interface definitions. -if_untrusted=eth0.1 -if_trusted=eth0.0 -if_vpn=vpn-+ -if_iodine=dns+ -if_its_mz=eth0.0 -if_its_pi=eth0.0 +## This router is involved in a routing asymmetry. +setconf(rp_filter, 0) +setconf(log_martians, 0) -m4_divert(-1) ###-------------------------------------------------------------------------- ### vampire-specific rules. -m4_divert(82)m4_dnl +m4_divert(86)m4_dnl ## Externally visible services. allowservices inbound tcp \ finger ident \ dns iodine \ ssh \ - smtp \ + smtp submission \ gnutella_svc \ ftp ftp_data \ rsync \ + imaps \ disorder mpd \ http https squid \ git \ @@ -57,22 +52,17 @@ allowservices inbound udp \ gnutella_svc \ i2p -## Provide DNS resolution to local untrusted hosts. -for p in tcp udp; do - run iptables -A inbound -j ACCEPT \ - -s 172.29.198.0/24 \ - -p $p --destination-port $port_dns -done +## Extend some services to local untrusted hosts. +clearchain inbound-untrusted +run iptables -A inbound -j inbound-untrusted \ + -s 172.29.198.0/24 -## Allow smb and nmb to untrusted hosts. This is a bit experimental. -run iptables -A inbound -j ACCEPT \ - -s 172.29.198.0/24 \ - -p udp -m multiport --destination-ports \ - $port_netbios_ns,$port_netbios_dgm -run iptables -A inbound -j ACCEPT \ - -s 172.29.198.0/24 \ - -p tcp -m multiport --destination-ports \ - $port_netbios_ssn,$port_microsoft_ds +allowservices inbound-untrusted tcp \ + dns \ + netbios_ssn microsoft_ds +allowservices inbound-untrusted udp \ + dns \ + tftp ## Provide syslog for evolution. run iptables -A inbound -j ACCEPT \ @@ -85,7 +75,7 @@ run iptables -A OUTPUT -m multiport \ ## Other interesting things. dnsresolver inbound -ntpclient inbound 158.152.1.76 158.152.1.204 194.159.253.2 +ntpclient inbound $ntp_servers m4_divert(-1) ###----- That's all, folks --------------------------------------------------