[fwbuilder-commits] r3086 - in branches/v4_0/test: iosacl ipf pf pix
Brought to you by:
mikehorn
From: <va...@in...> - 2010-07-15 17:10:07
|
Author: vadim Date: 2010-07-15 10:09:55 -0700 (Thu, 15 Jul 2010) New Revision: 3086 Modified: branches/v4_0/test/iosacl/objects-for-regression-tests.fwb branches/v4_0/test/ipf/objects-for-regression-tests.fwb branches/v4_0/test/pf/objects-for-regression-tests.fwb branches/v4_0/test/pix/objects-for-regression-tests.fwb Log: minor updates in test data files after they were loaded in the latest version of the gui Modified: branches/v4_0/test/iosacl/objects-for-regression-tests.fwb =================================================================== --- branches/v4_0/test/iosacl/objects-for-regression-tests.fwb 2010-07-15 17:09:25 UTC (rev 3085) +++ branches/v4_0/test/iosacl/objects-for-regression-tests.fwb 2010-07-15 17:09:55 UTC (rev 3086) @@ -101,17 +101,29 @@ <ServiceGroup id="stdid05" name="Services" comment="" ro="False"> <CustomService id="stdid14_1" name="ESTABLISHED" comment="This service matches all packets which are part of network connections established through the firewall, or connections 'related' to those established through the firewall. Term 'established' refers to the state tracking mechanism which exists inside iptables and other stateful firewalls and does not mean any particular combination of packet header options. Packet is considered to correspond to the state 'ESTABLISHED' if it belongs to the network session, for which proper initiation has been seen by the firewall, so its stateful inspection module made appropriate record in the state table. Usually stateful firewalls keep track of network connections using not only tcp protocol, but also udp and sometimes even icmp protocols. 'RELATED' describes packet belonging to a separate network connection, related to the session firewall is keeping track of. One example is FTP command and FTP data sessions." ro="False" prot ocol="any" address_family="ipv4"> <CustomServiceCommand platform="Undefined"></CustomServiceCommand> + <CustomServiceCommand platform="fwsm"></CustomServiceCommand> <CustomServiceCommand platform="iosacl">established</CustomServiceCommand> + <CustomServiceCommand platform="ipf"></CustomServiceCommand> <CustomServiceCommand platform="ipfilter"></CustomServiceCommand> <CustomServiceCommand platform="ipfw">established</CustomServiceCommand> <CustomServiceCommand platform="iptables">-m state --state ESTABLISHED,RELATED</CustomServiceCommand> + <CustomServiceCommand platform="pf"></CustomServiceCommand> + <CustomServiceCommand platform="pix"></CustomServiceCommand> + <CustomServiceCommand platform="procurve_acl">established</CustomServiceCommand> + <CustomServiceCommand platform="unknown"></CustomServiceCommand> </CustomService> <CustomService id="stdid14_2" name="ESTABLISHED ipv6" comment="This service matches all packets which are part of network connections established through the firewall, or connections 'related' to those established through the firewall. Term 'established' refers to the state tracking mechanism which exists inside iptables and other stateful firewalls and does not mean any particular combination of packet header options. Packet is considered to correspond to the state 'ESTABLISHED' if it belongs to the network session, for which proper initiation has been seen by the firewall, so its stateful inspection module made appropriate record in the state table. Usually stateful firewalls keep track of network connections using not only tcp protocol, but also udp and sometimes even icmp protocols. 'RELATED' describes packet belonging to a separate network connection, related to the session firewall is keeping track of. One example is FTP command and FTP data sessions." ro="False" protocol="any" address_family="ipv6"> <CustomServiceCommand platform="Undefined"></CustomServiceCommand> + <CustomServiceCommand platform="fwsm"></CustomServiceCommand> <CustomServiceCommand platform="iosacl">established</CustomServiceCommand> + <CustomServiceCommand platform="ipf"></CustomServiceCommand> <CustomServiceCommand platform="ipfilter"></CustomServiceCommand> <CustomServiceCommand platform="ipfw">established</CustomServiceCommand> <CustomServiceCommand platform="iptables">-m state --state ESTABLISHED,RELATED</CustomServiceCommand> + <CustomServiceCommand platform="pf"></CustomServiceCommand> + <CustomServiceCommand platform="pix"></CustomServiceCommand> + <CustomServiceCommand platform="procurve_acl">established</CustomServiceCommand> + <CustomServiceCommand platform="unknown"></CustomServiceCommand> </CustomService> <ServiceGroup id="stdid10" name="Groups" comment="" ro="False"> <ServiceGroup id="sg-DHCP" name="DHCP" comment="" ro="False"> Modified: branches/v4_0/test/ipf/objects-for-regression-tests.fwb =================================================================== --- branches/v4_0/test/ipf/objects-for-regression-tests.fwb 2010-07-15 17:09:25 UTC (rev 3085) +++ branches/v4_0/test/ipf/objects-for-regression-tests.fwb 2010-07-15 17:09:55 UTC (rev 3086) @@ -105,6 +105,7 @@ <CustomServiceCommand platform="ipfilter"></CustomServiceCommand> <CustomServiceCommand platform="ipfw">established</CustomServiceCommand> <CustomServiceCommand platform="iptables">-m state --state ESTABLISHED,RELATED</CustomServiceCommand> + <CustomServiceCommand platform="procurve_acl">established</CustomServiceCommand> </CustomService> <CustomService id="stdid14_2" name="ESTABLISHED ipv6" comment="This service matches all packets which are part of network connections established through the firewall, or connections 'related' to those established through the firewall. Term 'established' refers to the state tracking mechanism which exists inside iptables and other stateful firewalls and does not mean any particular combination of packet header options. Packet is considered to correspond to the state 'ESTABLISHED' if it belongs to the network session, for which proper initiation has been seen by the firewall, so its stateful inspection module made appropriate record in the state table. Usually stateful firewalls keep track of network connections using not only tcp protocol, but also udp and sometimes even icmp protocols. 'RELATED' describes packet belonging to a separate network connection, related to the session firewall is keeping track of. One example is FTP command and FTP data sessions." ro="False" protocol="any" address_family="ipv6"> <CustomServiceCommand platform="Undefined"></CustomServiceCommand> @@ -112,6 +113,7 @@ <CustomServiceCommand platform="ipfilter"></CustomServiceCommand> <CustomServiceCommand platform="ipfw">established</CustomServiceCommand> <CustomServiceCommand platform="iptables">-m state --state ESTABLISHED,RELATED</CustomServiceCommand> + <CustomServiceCommand platform="procurve_acl">established</CustomServiceCommand> </CustomService> <ServiceGroup id="stdid10" name="Groups" comment="" ro="False"> <ServiceGroup id="sg-DHCP" name="DHCP" comment="" ro="False"> Modified: branches/v4_0/test/pf/objects-for-regression-tests.fwb =================================================================== --- branches/v4_0/test/pf/objects-for-regression-tests.fwb 2010-07-15 17:09:25 UTC (rev 3085) +++ branches/v4_0/test/pf/objects-for-regression-tests.fwb 2010-07-15 17:09:55 UTC (rev 3086) @@ -101,17 +101,29 @@ <ServiceGroup id="stdid05" name="Services" comment="" ro="False"> <CustomService id="stdid14_1" name="ESTABLISHED" comment="This service matches all packets which are part of network connections established through the firewall, or connections 'related' to those established through the firewall. Term 'established' refers to the state tracking mechanism which exists inside iptables and other stateful firewalls and does not mean any particular combination of packet header options. Packet is considered to correspond to the state 'ESTABLISHED' if it belongs to the network session, for which proper initiation has been seen by the firewall, so its stateful inspection module made appropriate record in the state table. Usually stateful firewalls keep track of network connections using not only tcp protocol, but also udp and sometimes even icmp protocols. 'RELATED' describes packet belonging to a separate network connection, related to the session firewall is keeping track of. One example is FTP command and FTP data sessions." ro="False" prot ocol="any" address_family="ipv4"> <CustomServiceCommand platform="Undefined"></CustomServiceCommand> + <CustomServiceCommand platform="fwsm"></CustomServiceCommand> <CustomServiceCommand platform="iosacl">established</CustomServiceCommand> + <CustomServiceCommand platform="ipf"></CustomServiceCommand> <CustomServiceCommand platform="ipfilter"></CustomServiceCommand> <CustomServiceCommand platform="ipfw">established</CustomServiceCommand> <CustomServiceCommand platform="iptables">-m state --state ESTABLISHED,RELATED</CustomServiceCommand> + <CustomServiceCommand platform="pf"></CustomServiceCommand> + <CustomServiceCommand platform="pix"></CustomServiceCommand> + <CustomServiceCommand platform="procurve_acl">established</CustomServiceCommand> + <CustomServiceCommand platform="unknown"></CustomServiceCommand> </CustomService> <CustomService id="stdid14_2" name="ESTABLISHED ipv6" comment="This service matches all packets which are part of network connections established through the firewall, or connections 'related' to those established through the firewall. Term 'established' refers to the state tracking mechanism which exists inside iptables and other stateful firewalls and does not mean any particular combination of packet header options. Packet is considered to correspond to the state 'ESTABLISHED' if it belongs to the network session, for which proper initiation has been seen by the firewall, so its stateful inspection module made appropriate record in the state table. Usually stateful firewalls keep track of network connections using not only tcp protocol, but also udp and sometimes even icmp protocols. 'RELATED' describes packet belonging to a separate network connection, related to the session firewall is keeping track of. One example is FTP command and FTP data sessions." ro="False" protocol="any" address_family="ipv6"> <CustomServiceCommand platform="Undefined"></CustomServiceCommand> + <CustomServiceCommand platform="fwsm"></CustomServiceCommand> <CustomServiceCommand platform="iosacl">established</CustomServiceCommand> + <CustomServiceCommand platform="ipf"></CustomServiceCommand> <CustomServiceCommand platform="ipfilter"></CustomServiceCommand> <CustomServiceCommand platform="ipfw">established</CustomServiceCommand> <CustomServiceCommand platform="iptables">-m state --state ESTABLISHED,RELATED</CustomServiceCommand> + <CustomServiceCommand platform="pf"></CustomServiceCommand> + <CustomServiceCommand platform="pix"></CustomServiceCommand> + <CustomServiceCommand platform="procurve_acl">established</CustomServiceCommand> + <CustomServiceCommand platform="unknown"></CustomServiceCommand> </CustomService> <ServiceGroup id="stdid10" name="Groups" comment="" ro="False"> <ServiceGroup id="sg-DHCP" name="DHCP" comment="" ro="False"> Modified: branches/v4_0/test/pix/objects-for-regression-tests.fwb =================================================================== --- branches/v4_0/test/pix/objects-for-regression-tests.fwb 2010-07-15 17:09:25 UTC (rev 3085) +++ branches/v4_0/test/pix/objects-for-regression-tests.fwb 2010-07-15 17:09:55 UTC (rev 3086) @@ -101,29 +101,19 @@ <ServiceGroup id="stdid05" name="Services" comment="" ro="False"> <CustomService id="stdid14_1" name="ESTABLISHED" comment="This service matches all packets which are part of network connections established through the firewall, or connections 'related' to those established through the firewall. Term 'established' refers to the state tracking mechanism which exists inside iptables and other stateful firewalls and does not mean any particular combination of packet header options. Packet is considered to correspond to the state 'ESTABLISHED' if it belongs to the network session, for which proper initiation has been seen by the firewall, so its stateful inspection module made appropriate record in the state table. Usually stateful firewalls keep track of network connections using not only tcp protocol, but also udp and sometimes even icmp protocols. 'RELATED' describes packet belonging to a separate network connection, related to the session firewall is keeping track of. One example is FTP command and FTP data sessions." ro="False" prot ocol="any" address_family="ipv4"> <CustomServiceCommand platform="Undefined"></CustomServiceCommand> - <CustomServiceCommand platform="fwsm"></CustomServiceCommand> <CustomServiceCommand platform="iosacl">established</CustomServiceCommand> - <CustomServiceCommand platform="ipf"></CustomServiceCommand> <CustomServiceCommand platform="ipfilter"></CustomServiceCommand> <CustomServiceCommand platform="ipfw">established</CustomServiceCommand> <CustomServiceCommand platform="iptables">-m state --state ESTABLISHED,RELATED</CustomServiceCommand> - <CustomServiceCommand platform="pf"></CustomServiceCommand> - <CustomServiceCommand platform="pix"></CustomServiceCommand> <CustomServiceCommand platform="procurve_acl">established</CustomServiceCommand> - <CustomServiceCommand platform="unknown"></CustomServiceCommand> </CustomService> <CustomService id="stdid14_2" name="ESTABLISHED ipv6" comment="This service matches all packets which are part of network connections established through the firewall, or connections 'related' to those established through the firewall. Term 'established' refers to the state tracking mechanism which exists inside iptables and other stateful firewalls and does not mean any particular combination of packet header options. Packet is considered to correspond to the state 'ESTABLISHED' if it belongs to the network session, for which proper initiation has been seen by the firewall, so its stateful inspection module made appropriate record in the state table. Usually stateful firewalls keep track of network connections using not only tcp protocol, but also udp and sometimes even icmp protocols. 'RELATED' describes packet belonging to a separate network connection, related to the session firewall is keeping track of. One example is FTP command and FTP data sessions." ro="False" protocol="any" address_family="ipv6"> <CustomServiceCommand platform="Undefined"></CustomServiceCommand> - <CustomServiceCommand platform="fwsm"></CustomServiceCommand> <CustomServiceCommand platform="iosacl">established</CustomServiceCommand> - <CustomServiceCommand platform="ipf"></CustomServiceCommand> <CustomServiceCommand platform="ipfilter"></CustomServiceCommand> <CustomServiceCommand platform="ipfw">established</CustomServiceCommand> <CustomServiceCommand platform="iptables">-m state --state ESTABLISHED,RELATED</CustomServiceCommand> - <CustomServiceCommand platform="pf"></CustomServiceCommand> - <CustomServiceCommand platform="pix"></CustomServiceCommand> <CustomServiceCommand platform="procurve_acl">established</CustomServiceCommand> - <CustomServiceCommand platform="unknown"></CustomServiceCommand> </CustomService> <ServiceGroup id="stdid10" name="Groups" comment="" ro="False"> <ServiceGroup id="sg-DHCP" name="DHCP" comment="" ro="False"> |