From f3f390bc6f8cbb9426cebe4578ceda9224805c7e Mon Sep 17 00:00:00 2001 From: Mark Wooding Date: Sat, 23 Jul 2011 11:19:29 +0100 Subject: [PATCH] jem.m4: Remove SMB for untrusted hosts. Leave that as a job for artist. --- jem.m4 | 10 ---------- 1 file changed, 10 deletions(-) diff --git a/jem.m4 b/jem.m4 index 78574f1..26f1398 100644 --- a/jem.m4 +++ b/jem.m4 @@ -65,15 +65,5 @@ for p in tcp udp; do -p $p --destination-port $port_dns done -## Allow smb and nmb to untrusted hosts. This is a bit experimental. -run iptables -A inbound -j ACCEPT \ - -s 172.29.198.0/24 \ - -p udp -m multiport --destination-ports \ - $port_netbios_ns,$port_netbios_dgm -run iptables -A inbound -j ACCEPT \ - -s 172.29.198.0/24 \ - -p tcp -m multiport --destination-ports \ - $port_netbios_ssn,$port_microsoft_ds - m4_divert(-1) ###----- That's all, folks -------------------------------------------------- -- 2.11.0