#Generated by nupyf on 2008-10-03 13:34:35.132647 from ./features/acls_ordering_auth.xml #Rules for FORWARD #http lan vers internet (acl 1) #https lan vers internet (acl 2) #http lan vers internet (acl 1) -A DMZ-INTERNET -p tcp --dport 80 --sport 1024:65535 -m state --state NEW --syn -j NFQUEUE --queue-num 0 # 1 2 #https lan vers internet (acl 2) -A DMZ-INTERNET -p tcp --dport 443 --sport 1024:65535 -m state --state NEW --syn -j NFQUEUE --queue-num 0 # 2 2 #https lan vers internet (acl 2) #http lan vers internet (acl 1) #https lan vers internet (acl 2) -A INTRANET-INTERNET -p tcp --dport 443 --sport 1024:65535 -m state --state NEW --syn -j NFQUEUE --queue-num 0 # 2 1 #http lan vers internet (acl 1) -A INTRANET-INTERNET -p tcp --dport 80 --sport 1024:65535 -m state --state NEW --syn -j NFQUEUE --queue-num 0 # 1 1 -A INTERNET-INTERNET -j ULOG --ulog-prefix "F0D:INTERNET-INTERNET DROP" -A INTERNET-INTERNET -j DROP -A INTERNET-DMZ -j ULOG --ulog-prefix "F0D:INTERNET-DMZ DROP" -A INTERNET-DMZ -j DROP -A INTERNET-INTRANET -j ULOG --ulog-prefix "F0D:INTERNET-INTRANET DROP" -A INTERNET-INTRANET -j DROP -A DMZ-INTERNET -j ULOG --ulog-prefix "F0D:DMZ-INTERNET DROP" -A DMZ-INTERNET -j DROP -A DMZ-DMZ -j ULOG --ulog-prefix "F0D:DMZ-DMZ DROP" -A DMZ-DMZ -j DROP -A DMZ-INTRANET -j ULOG --ulog-prefix "F0D:DMZ-INTRANET DROP" -A DMZ-INTRANET -j DROP -A INTRANET-INTERNET -j ULOG --ulog-prefix "F0D:INTRANET-INTERNET DROP" -A INTRANET-INTERNET -j DROP -A INTRANET-DMZ -j ULOG --ulog-prefix "F0D:INTRANET-DMZ DROP" -A INTRANET-DMZ -j DROP -A INTRANET-INTRANET -j ULOG --ulog-prefix "F0D:INTRANET-INTRANET DROP" -A INTRANET-INTRANET -j DROP