Created
April 6, 2011 11:54
-
-
Save funollet/905524 to your computer and use it in GitHub Desktop.
ferm.conf @ stallman
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# ferm.conf @ stallman | |
# Llistat de IPs de les quals accepta correu. | |
@def $MX_SERVER = (147.83.2.50 147.83.2.51) ; | |
table filter { | |
chain INPUT { | |
policy DROP; | |
# Connection tracking. | |
mod state state INVALID DROP; | |
mod state state (ESTABLISHED RELATED) ACCEPT; | |
# Allow local connections. | |
interface lo ACCEPT; | |
# Permet ping. | |
protocol icmp icmp-type echo-request ACCEPT; | |
# Serveis oberts a tot-hom. | |
protocol tcp dport (ssh http https) ACCEPT; | |
# Accepta ftp, ftp-data i rang de ports per ftp passiu. | |
protocol tcp dport (20 21 50000:60000) ACCEPT; | |
# Accepta DNS. | |
protocol (tcp udp) dport domain ACCEPT; | |
# Accepta correu dels servidors de la UPC. | |
saddr $MX_SERVER protocol tcp dport (smtp ssmtp) ACCEPT; | |
# Genera logs de les connexions denegades. | |
LOG log-prefix "iptables/DROP: " ; | |
} | |
# outgoing connections are not limited | |
chain OUTPUT policy ACCEPT; | |
# this is not a router | |
chain FORWARD policy DROP; | |
} |
Author
funollet
commented
Apr 6, 2011
En principi em sembla bé, per mi endavant.
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment