Advertisement
Guest User

Untitled

a guest
Jun 26th, 2017
91
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.82 KB | None | 0 0
  1. Shorewall
  2. #############################################################################################################
  3. #ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/
  4. # PORT PORT(S) DEST LIMIT GROUP
  5. # PORT PORT(S) DEST LIMIT GROUP
  6. #
  7. # Accept DNS connections from the firewall to the network
  8. #
  9. DNS/ACCEPT $FW net
  10. DNS/ACCEPT loc $FW
  11. DNS/ACCEPT loc net
  12. #
  13. # Accept SSH connections from the local network for administration
  14. #
  15. SSH/ACCEPT all $FW
  16. SSH/ACCEPT $FW all
  17.  
  18. ACCEPT vpn all
  19. ACCEPT all vpn
  20.  
  21. #
  22. # Allow Ping from the local network
  23. #
  24. Ping/ACCEPT loc $FW
  25. Ping/ACCEPT net $FW
  26. Ping/ACCEPT loc net
  27. Ping/ACCEPT $FW all
  28.  
  29. #ACCEPT $FW loc icmp
  30. ACCEPT $FW net icmp
  31. #
  32.  
  33. ACCEPT loc $FW udp
  34. ACCEPT $FW loc udp
  35.  
  36. ACCEPT net $FW tcp 80
  37. #ACCEPT net:194.105.227.102 $FW tcp 80
  38.  
  39. ACCEPT loc net:10.10.21.225 all
  40. #Tel-Log
  41. ACCEPT:info loc net tcp 3553
  42.  
  43. #Remote tenging inn
  44. # Marorka
  45. DNAT net loc:192.168.1.230 tcp 3389
  46. ACCEPT loc:192.168.1.230 net tcp 80
  47.  
  48. # RDP gw ut
  49. ACCEPT loc net tcp 3389
  50. ACCEPT loc:192.168.1.176 net tcp 443
  51.  
  52. #Sailor ACU
  53. #DNAT net net:192.168.100.2:80 tcp 443
  54. ACCEPT net:10.10.12.247 $FW all
  55. # vef
  56. ACCEPT $FW loc tcp 80
  57. #myndavelar securitas
  58. DNAT net loc:192.168.1.200 tcp 80
  59. DNAT net loc:192.168.1.201 tcp 9001
  60. DNAT net loc:192.168.1.202 tcp 9002
  61. DNAT net loc:192.168.1.203 tcp 9003
  62. DNAT net loc:192.168.1.204 tcp 9004
  63. DNAT net loc:192.168.1.205 tcp 9005
  64. DNAT net loc:192.168.1.206 tcp 9006
  65. DNAT net loc:192.168.1.207 tcp 9007
  66.  
  67. #ACCEPT net $FW tcp 9001
  68.  
  69. # temp access
  70. ACCEPT loc:192.168.1.100 net all
  71.  
  72. #Proxy
  73. ACCEPT loc $FW tcp 3128
  74.  
  75. # email
  76. ACCEPT loc net tcp 465
  77. ACCEPT loc net tcp 995
  78. ACCEPT loc net tcp 587
  79. ACCEPT loc net tcp 993
  80.  
  81. #FTP/NTP/TFTP
  82. #FTP/ACCEPT loc $FW
  83. NTP/ACCEPT loc $FW
  84. #ACCEPT loc $FW udp 69
  85.  
  86. # Add the following to stop a rouge machine on the local network from
  87. # connecting to this machine!
  88. #DROP loc:192.168.70.104 $FW tcp - -
  89. DROP loc:192.168.1.177 net:8.254.194.46 tcp - -
  90. DROP loc:192.168.1.177 net:8.254.54.254 tcp - -
  91.  
  92. #Maxsea
  93. ACCEPT loc:192.168.1.56 net all
  94.  
  95.  
  96. # fix fyrir update
  97. ACCEPT loc:192.168.1.112 net all
  98. ACCEPT loc:192.168.1.105 net all
  99. # Trend Micro
  100. ACCEPT loc net tcp 62777
  101.  
  102. # verkbokhald EB
  103. ACCEPT loc net:212.30.252.101 tcp 8080
  104.  
  105. #Full access network (DREAMBOX druslur)
  106. ACCEPT loc:192.168.1.170 net all
  107. ACCEPT loc:192.168.1.171 net all
  108. ACCEPT loc:192.168.1.172 net all
  109. ACCEPT loc:192.168.1.173 net all
  110. ACCEPT loc:192.168.1.174 net all
  111. ACCEPT loc:192.168.1.175 net all
  112. ACCEPT loc:192.168.1.176 net all
  113. #temp lokun 18.juli
  114. #ACCEPT loc:192.168.1.177 net all
  115. ACCEPT loc:192.168.1.178 net all
  116. ACCEPT loc:192.168.1.179 net all
  117.  
  118.  
  119. # Mariconnect 178.19.53.5
  120. #ACCEPT loc:192.168.1.229 net tcp 22
  121. #DNAT net:178.19.53.5 loc:192.168.1.229:22 tcp 2222
  122. #DNAT net loc:192.168.1.229:22 tcp 2222
  123.  
  124. #Optimar
  125. #ACCEPT loc:192.168.1.180 net all
  126.  
  127. # CatSat vedurgogn
  128. ACCEPT loc net:62.193.60.36 all
  129. ACCEPT loc:192.168.1.40 net all
  130.  
  131.  
  132. #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement