Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- vyatta@R1:~$ configure
- [edit]
- vyatta@R1# show firewall
- name local-two {
- enable-default-log
- rule 10 {
- action accept
- state {
- established enable
- }
- }
- }
- name one-two {
- enable-default-log
- rule 10 {
- action accept
- destination {
- port 90
- }
- protocol tcp
- }
- }
- name two-local {
- default-action drop
- enable-default-log
- rule 10 {
- action accept
- destination {
- port 22,23
- }
- protocol tcp
- }
- }
- name two-one {
- enable-default-log
- rule 10 {
- action accept
- state {
- established enable
- }
- }
- }
- [edit]
- vyatta@R1# show zone-policy
- zone local {
- from two {
- firewall {
- name two-local
- }
- }
- local-zone
- }
- zone one {
- from two {
- firewall {
- name two-one
- }
- }
- interface eth0
- }
- zone two {
- from local {
- firewall {
- name local-two
- }
- }
- from one {
- firewall {
- name one-two
- }
- }
- interface eth2
- interface eth1
- }
- [edit]
- vyatta@R1#
- [edit]
- vyatta@R1# sudo iptables -vnL
- Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 190 10702 VZONE_local_IN all -- * * 0.0.0.0/0 0.0.0.0/0
- 72783 38M VYATTA_POST_FW_HOOK all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 VYATTA_IN_HOOK all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 VYATTA_OUT_HOOK all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 VZONE_one all -- * eth0 0.0.0.0/0 0.0.0.0/0
- 0 0 VZONE_two all -- * eth2 0.0.0.0/0 0.0.0.0/0
- 0 0 VZONE_two all -- * eth1 0.0.0.0/0 0.0.0.0/0
- 713 96093 VYATTA_POST_FW_HOOK all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain OUTPUT (policy ACCEPT 74942 packets, 12M bytes)
- pkts bytes target prot opt in out source destination
- 150 11461 VZONE_local_OUT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain VYATTA_IN_HOOK (1 references)
- pkts bytes target prot opt in out source destination
- Chain VYATTA_OUT_HOOK (1 references)
- pkts bytes target prot opt in out source destination
- Chain VYATTA_POST_FW_HOOK (2 references)
- pkts bytes target prot opt in out source destination
- 23962 3460K VYATTA_SNORT_all_HOOK all -- * * 0.0.0.0/0 0.0.0.0/0
- 29 2134 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain VYATTA_SNORT_all_HOOK (1 references)
- pkts bytes target prot opt in out source destination
- 73467 38M QUEUE all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain VZONE_local_IN (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 RETURN all -- lo * 0.0.0.0/0 0.0.0.0/0
- 0 0 two-local all -- eth2 * 0.0.0.0/0 0.0.0.0/0
- 0 0 RETURN all -- eth2 * 0.0.0.0/0 0.0.0.0/0
- 135 7170 two-local all -- eth1 * 0.0.0.0/0 0.0.0.0/0
- 132 6990 RETURN all -- eth1 * 0.0.0.0/0 0.0.0.0/0
- 33 2169 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain VZONE_local_OUT (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 RETURN all -- * lo 0.0.0.0/0 0.0.0.0/0
- 12 720 local-two all -- * eth2 0.0.0.0/0 0.0.0.0/0
- 0 0 RETURN all -- * eth2 0.0.0.0/0 0.0.0.0/0
- 79 6141 local-two all -- * eth1 0.0.0.0/0 0.0.0.0/0
- 79 6141 RETURN all -- * eth1 0.0.0.0/0 0.0.0.0/0
- 42 3448 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain VZONE_one (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 RETURN all -- eth0 * 0.0.0.0/0 0.0.0.0/0
- 0 0 two-one all -- eth2 * 0.0.0.0/0 0.0.0.0/0
- 0 0 RETURN all -- eth2 * 0.0.0.0/0 0.0.0.0/0
- 0 0 two-one all -- eth1 * 0.0.0.0/0 0.0.0.0/0
- 0 0 RETURN all -- eth1 * 0.0.0.0/0 0.0.0.0/0
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain VZONE_two (2 references)
- pkts bytes target prot opt in out source destination
- 0 0 RETURN all -- eth1 * 0.0.0.0/0 0.0.0.0/0
- 0 0 RETURN all -- eth2 * 0.0.0.0/0 0.0.0.0/0
- 0 0 one-two all -- eth0 * 0.0.0.0/0 0.0.0.0/0
- 0 0 RETURN all -- eth0 * 0.0.0.0/0 0.0.0.0/0
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain local-two (2 references)
- pkts bytes target prot opt in out source destination
- 90 6933 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 /* local-two-10 */ state ESTABLISHED
- 18 1080 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 /* local-two-10000 default-action drop */ LOG flags 0 level 4 prefix `[local-two-default-D]'
- 18 1080 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 /* local-two-10000 default-action drop */
- Chain one-two (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 /* one-two-10 */ tcp dpt:90
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 /* one-two-10000 default-action drop */ LOG flags 0 level 4 prefix `[one-two-default-D]'
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 /* one-two-10000 default-action drop */
- Chain two-local (2 references)
- pkts bytes target prot opt in out source destination
- 132 6990 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 /* two-local-10 */ multiport dports 22,23
- 25 1543 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 /* two-local-10000 default-action drop */ LOG flags 0 level 4 prefix `[two-local-default-D]'
- 25 1543 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 /* two-local-10000 default-action drop */
- Chain two-one (2 references)
- pkts bytes target prot opt in out source destination
- 0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 /* two-one-10 */ state ESTABLISHED
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 /* two-one-10000 default-action drop */ LOG flags 0 level 4 prefix `[two-one-default-D]'
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 /* two-one-10000 default-action drop */
- [edit]
- vyatta@R1# delete zone-policy
- [edit]
- vyatta@R1# commit
- [edit]
- vyatta@R1#
- [edit]
- vyatta@R1# sudo iptables -vnL
- Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 72833 38M VYATTA_POST_FW_HOOK all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 VYATTA_IN_HOOK all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 VYATTA_OUT_HOOK all -- * * 0.0.0.0/0 0.0.0.0/0
- 713 96093 VYATTA_POST_FW_HOOK all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain OUTPUT (policy ACCEPT 74975 packets, 12M bytes)
- pkts bytes target prot opt in out source destination
- Chain VYATTA_IN_HOOK (1 references)
- pkts bytes target prot opt in out source destination
- Chain VYATTA_OUT_HOOK (1 references)
- pkts bytes target prot opt in out source destination
- Chain VYATTA_POST_FW_HOOK (2 references)
- pkts bytes target prot opt in out source destination
- 24012 3462K VYATTA_SNORT_all_HOOK all -- * * 0.0.0.0/0 0.0.0.0/0
- 29 2134 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain VYATTA_SNORT_all_HOOK (1 references)
- pkts bytes target prot opt in out source destination
- 73517 38M QUEUE all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain local-two (0 references)
- pkts bytes target prot opt in out source destination
- 115 15211 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 /* local-two-10 */ state ESTABLISHED
- 19 1140 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 /* local-two-10000 default-action drop */ LOG flags 0 level 4 prefix `[local-two-default-D]'
- 19 1140 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 /* local-two-10000 default-action drop */
- Chain one-two (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 /* one-two-10 */ tcp dpt:90
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 /* one-two-10000 default-action drop */ LOG flags 0 level 4 prefix `[one-two-default-D]'
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 /* one-two-10000 default-action drop */
- Chain two-local (0 references)
- pkts bytes target prot opt in out source destination
- 170 8983 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 /* two-local-10 */ multiport dports 22,23
- 25 1543 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 /* two-local-10000 default-action drop */ LOG flags 0 level 4 prefix `[two-local-default-D]'
- 25 1543 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 /* two-local-10000 default-action drop */
- Chain two-one (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 /* two-one-10 */ state ESTABLISHED
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 /* two-one-10000 default-action drop */ LOG flags 0 level 4 prefix `[two-one-default-D]'
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 /* two-one-10000 default-action drop */
- [edit]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement