Skip to content

Instantly share code, notes, and snippets.

@michaelcoyote
Created August 28, 2014 00:18
Show Gist options
  • Star 1 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save michaelcoyote/dbd177e25f7e591239cc to your computer and use it in GitHub Desktop.
Save michaelcoyote/dbd177e25f7e591239cc to your computer and use it in GitHub Desktop.
A collection of NetWorker iptables rules for NetWorker
#App,Destination,Source,Service, Port, Port Type
#DPA,dpaserv,managment-net,SSH,22, TCP
#DPA,dpaserv,managment-net,SNMP,161, TCP
#DPA,dpaserv,managment-net,DPA HTTPS 9002 TCP
#DPA,dpaserv,managment-net,DPA HTTPS 9002 TCP
#DPA,dpaserv,managment-net,DPA HTTP, 9003, TCP
#DPA,dpaserv,managment-net,DPA HTTP, 9004, TCP
#DPA,server-agents,dpaserv,DPA Agent - HTTP, 3741, TCP
#
#App,Destination,Source,Service,Dest Port, Src Port Proto
#NetWorker,nwserver,ANY,SSH,22,ANY,TCP
#NetWorker,nwserver,ANY_CLIENT,portmap,111,ANY,TCP
#NetWorker,nwserver,ANY_CLIENT,portmap,111,ANY,UDP
#NetWorker,nwserver,ANY_CLIENT,nsrexecd,7937:9936,10001:30000,TCP
#NetWorker,nwserver,ANY_CLIENT,nsrexecd,7937:9936,10001:30000,UDP
#NetWorker,ANY_CLIENT,nwserver,nsr,10001:30000,7937:9936,TCP
#NetWorker,ANY_CLIENT,nwserver,nsr,10001:30000,7937:9936,UDP
-A INPUT -s nwserver 111 -d 0/0 -p tcp -y -i eth0 -j ACCEPT
-A INPUT -s nwserver 111 -d 0/0 -p udp -i eth0 -j ACCEPT
-A INPUT -s nwserver 7937 -d 0/0 -p tcp -y -i eth0 -j ACCEPT
-A INPUT -s nwserver 7937:7938 -d 0/0 -p udp -i eth0 -j ACCEPT
-A INPUT -s nwserver 10001:30000 -d 0/0 -p tcp -y -i eth0 -j ACCEPT
-A INPUT -s nwserver 10001:30000 -d 0/0 -p udp -i eth0 -j ACCEPT
#
# NetWorker Managment Console from a network and a client
-A INPUT -s 172.17.15.0/24 -p tcp -m tcp --dport 9000 -m state --state NEW -j ACCEPT
-A INPUT -s 10.12.1.2/32 -p tcp -m tcp --dport 9000 -m state --state NEW -j ACCEPT
#
# Networker ports from/to Storage Node
-A INPUT -s nwsn -p tcp -m tcp --dport 111 --state NEW -j ACCEPT
-A INPUT -s nwsn -p udp -m udp --dport 111 --state NEW -j ACCEPT
-A INPUT -s nwsn -p udp -m udp --dport 7937:9936 -sport 10001:30000 --state NEW -j ACCEPT
-A INPUT -s nwsn -p tcp -m tcp --dport 7937:9936 -sport 10001:30000 --state NEW -j ACCEPT
#
# NetWorker ports from/to 10.12.2.0/24 network
-A INPUT -s 10.12.2.0/24 -p udp -m udp --dport 111 --state NEW -j ACCEPT
-A INPUT -s 10.12.2.0/24 -p tcp -m tcp --dport 111 --state NEW -j ACCEPT
-A INPUT -s 10.12.2.0/24 -p udp -m udp --dport 7937:9936 -sport 10001:30000 --state NEW -j ACCEPT
-A INPUT -s 10.12.2.0/24 -p tcp -m tcp --dport 7937:9936 -sport 10001:30000 --state NEW -j ACCEPT
#
# DPA incoming
-A INPUT -s dpaserv -p tcp -m tcp --dport 3741 -m state --state NEW -j ACCEPT
# /etc/sysconfig/iptables
-A INPUT -m tcp -p tcp -s <client_network> --dport 7937:9936 -j ACCEPT
-A INPUT -m udp -p udp -s <client_network> --dport 7938 -j ACCEPT
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment