|
From: <bl...@pr...> - 2004-01-26 15:13:07
|
Update of /cvsroot/devil-linux/build/config/etc/init.d In directory sc8-pr-cvs1.sourceforge.net:/tmp/cvs-serv17486 Modified Files: firewall.rules.2nic firewall.rules.3nic Log Message: Added commented examples to open a port to the DL box. Index: firewall.rules.2nic =================================================================== RCS file: /cvsroot/devil-linux/build/config/etc/init.d/firewall.rules.2nic,v retrieving revision 1.10 retrieving revision 1.11 diff -u -d -r1.10 -r1.11 --- firewall.rules.2nic 21 Oct 2003 13:55:10 -0000 1.10 +++ firewall.rules.2nic 26 Jan 2004 02:57:22 -0000 1.11 @@ -75,6 +75,10 @@ # ${IPTABLES} -A PREROUTING -i ${OUT_DEV} -t nat -p TCP --dport $PORT -j DNAT --to ${SERVER_IP}:${PORT} # ${IPTABLES} -A FORWARD -p TCP -d ${SERVER_IP} --dport $PORT -i ${OUT_DEV} -o ${INT_DEV} -j ACCEPT +# Uncomment/modify the next 2 lines to open a port on the internet to Devil Linux. +# PORT=25 # 25 = SMTP. Change to the port you wish to open. +# ${IPTABLES} -A INPUT -p tcp --dport $PORT -i ${OUT_DEV} -j ACCEPT + # Block invalid connections from the internet. [ -n "$LOGGING" ] && \ ${IPTABLES} -A FORWARD -m state --state NEW,INVALID -i ${OUT_DEV} -j LOG --log-prefix "FORWARD INVALID: " Index: firewall.rules.3nic =================================================================== RCS file: /cvsroot/devil-linux/build/config/etc/init.d/firewall.rules.3nic,v retrieving revision 1.7 retrieving revision 1.8 diff -u -d -r1.7 -r1.8 --- firewall.rules.3nic 21 Oct 2003 13:55:10 -0000 1.7 +++ firewall.rules.3nic 26 Jan 2004 02:57:22 -0000 1.8 @@ -87,6 +87,10 @@ # ${IPTABLES} -A PREROUTING -i ${OUT_DEV} -t nat -p TCP --dport $PORT -j DNAT --to ${SERVER_IP}:${PORT} # ${IPTABLES} -A FORWARD -p TCP -d ${SERVER_IP} --dport $PORT -i ${OUT_DEV} -o ${DMZ_DEV} -j ACCEPT +# Uncomment/modify the next 2 lines to open a port on the DMZ to Devil Linux. +# PORT=25 # 25 = SMTP. Change to the port you wish to open. +# ${IPTABLES} -A INPUT -p tcp --dport $PORT -i ${DMZ_DEV} -j ACCEPT + # Block invalid connections from the internet. [ -n "$LOGGING" ] && \ ${IPTABLES} -A FORWARD -m state --state NEW,INVALID -i ${OUT_DEV} -j LOG --log-prefix "FORWARD INVALID: " |