X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~mdw/git/firewall/blobdiff_plain/36307da92b89c2413f49e2b705f73b2d1ec4e849..d0409c909cb113596f5d0daed5be237a42878c8d:/ibanez.m4 diff --git a/ibanez.m4 b/ibanez.m4 index f826e04..617200b 100644 --- a/ibanez.m4 +++ b/ibanez.m4 @@ -21,35 +21,30 @@ ### along with this program; if not, write to the Free Software Foundation, ### Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. -###-------------------------------------------------------------------------- -### Config settings. - -## This host isn't a router. -setconf(forward, 0) - -###-------------------------------------------------------------------------- -### Network interfaces. - -m4_divert(44)m4_dnl -## Interface definitions. -if_untrusted=br0 -if_trusted=br0 -if_vpn=br0 -if_iodine=br0 -if_its_mz=br0 -if_its_pi=br0 - -m4_divert(-1) ###-------------------------------------------------------------------------- ### ibanez-specific rules. -m4_divert(82)m4_dnl +m4_divert(86)m4_dnl ## Externally visible services. allowservices inbound tcp \ - ssh + ssh \ + ident +allowservices inbound udp \ + udpkey ## We have to provide NTP service. The guests sync to our clock. -ntpclient inbound 158.152.1.76 158.152.1.204 194.159.253.2 +ntpclient inbound $ntp_servers + +## Provide NTP service to untrusted clients. +iptables -A inbound -p udp -j ACCEPT \ + --source-port 123 --destination-port 123 \ + -s 172.29.198.0/23 +ip6tables -A inbound -p udp -j ACCEPT \ + --source-port 123 --destination-port 123 \ + -s 2001:ba8:1d9::/48 +ip6tables -A inbound -p udp -j ACCEPT \ + --source-port 123 --destination-port 123 \ + -s 2001:8b0:c92::/48 m4_divert(-1) ###----- That's all, folks --------------------------------------------------