chiark / gitweb /
Merge branch 'master' of metalzone:public-git/firewall
authorMark Wooding <mdw@distorted.org.uk>
Sat, 17 Apr 2010 15:37:28 +0000 (16:37 +0100)
committerMark Wooding <mdw@distorted.org.uk>
Sat, 17 Apr 2010 15:37:28 +0000 (16:37 +0100)
* 'master' of metalzone:public-git/firewall:
  functions.m4, local.m4: Handle fragments in a useful way.
  classify.m4: Correct summary line at the top.
  vampire.m4: Remove the magical DNS DDoS hack.

local.m4
metalzone.m4
numbers.m4
vampire.m4

index 2b1b898198f49ca0c5fb52de51471a5fc8f20194..b321cde9f86d341fda8be5f657ef4823d52e6a32 100644 (file)
--- a/local.m4
+++ b/local.m4
@@ -43,9 +43,10 @@ defiface $if_trusted \
        safe:172.29.199.64/27 \
        untrusted:default
 defiface $if_untrusted \
-       untrusted:172.29.198.0/24
+       untrusted:172.29.198.0/25
 defvpn $if_vpn safe 172.29.199.128/27 \
        crybaby:172.29.199.129
+defiface $if_iodine untrusted:172.29.198.128/28
 defiface $if_its_mz safe:172.29.199.160/30
 defiface $if_its_pi safe:192.168.0.0/24
 
index 62804c62ba40277eae1c21c54a1638493125e6c6..eb4dd2bf27bd26050f561e4d886403dceb93a7f6 100644 (file)
@@ -29,6 +29,7 @@ m4_divert(44)m4_dnl
 if_untrusted=eth0
 if_trusted=eth0
 if_vpn=eth0
+if_iodine=eth0
 if_its_mz=its-mz
 if_its_pi=its-pi
 
index 83de747e847b7aec8218cd0d2a177c44d71d46d0..9596c96d273913dc7074bd6f7e02bc236b61fd0c 100644 (file)
@@ -40,11 +40,14 @@ defport syslog 514                  # UDP only!
 defport rsync 873
 defport squid 3128
 defport tripe 4070
+defport iodine 5353
 defport postgresql 5432
 defport gnutella_svc 6346
+defport mpd 6600
 defport tor_public 9001
 defport tor_directory 9030
 defport git 9418
+defport disorder 23599
 
 m4_divert(-1)
 ###----- That's all, folks --------------------------------------------------
index 13e37bd6477ea550b2ec6054c6ac8bcdae396a8a..2f8c105c28743befd910824b679845de866f3ed4 100644 (file)
@@ -29,6 +29,7 @@ m4_divert(44)m4_dnl
 if_untrusted=eth0.1
 if_trusted=eth0.0
 if_vpn=vpn-+
+if_iodine=dns+
 if_its_mz=eth0.0
 if_its_pi=eth0.0
 
@@ -40,18 +41,19 @@ m4_divert(82)m4_dnl
 ## Externally visible services.
 allowservices inbound tcp \
        finger ident \
-       dns \
+       dns iodine \
        ssh \
        smtp \
        gnutella_svc \
        ftp ftp_data \
        rsync \
+       disorder \
        http https \
        git     
 allowservices inbound tcp \
        tor_public tor_directory
 allowservices inbound udp \
-       dns \
+       dns iodine \
        tripe \
        gnutella_svc