Sophie

Sophie

distrib > Mandriva > 2010.0 > i586 > media > contrib-release > by-pkgid > dca483b59ba61f3fa092de932ddd570e > files > 861

nuface-2.0.14-2mdv2009.1.i586.rpm

#Generated by nupyf on 2008-10-03 13:34:35.132647 from ./features/acls_ordering_auth.xml

#Rules for FORWARD

#http lan vers internet (acl 1)

#https lan vers internet (acl 2)



#http lan vers internet (acl 1)
-A DMZ-INTERNET -p tcp --dport 80 --sport 1024:65535 -m state --state NEW --syn -j NFQUEUE --queue-num 0  # 1 2

#https lan vers internet (acl 2)
-A DMZ-INTERNET -p tcp --dport 443 --sport 1024:65535 -m state --state NEW --syn -j NFQUEUE --queue-num 0  # 2 2



#https lan vers internet (acl 2)

#http lan vers internet (acl 1)



#https lan vers internet (acl 2)
-A INTRANET-INTERNET -p tcp --dport 443 --sport 1024:65535 -m state --state NEW --syn -j NFQUEUE --queue-num 0  # 2 1

#http lan vers internet (acl 1)
-A INTRANET-INTERNET -p tcp --dport 80 --sport 1024:65535 -m state --state NEW --syn -j NFQUEUE --queue-num 0  # 1 1


-A INTERNET-INTERNET -j ULOG --ulog-prefix "F0D:INTERNET-INTERNET DROP"
-A INTERNET-INTERNET -j DROP

-A INTERNET-DMZ -j ULOG --ulog-prefix "F0D:INTERNET-DMZ DROP"
-A INTERNET-DMZ -j DROP

-A INTERNET-INTRANET -j ULOG --ulog-prefix "F0D:INTERNET-INTRANET DROP"
-A INTERNET-INTRANET -j DROP

-A DMZ-INTERNET -j ULOG --ulog-prefix "F0D:DMZ-INTERNET DROP"
-A DMZ-INTERNET -j DROP

-A DMZ-DMZ -j ULOG --ulog-prefix "F0D:DMZ-DMZ DROP"
-A DMZ-DMZ -j DROP

-A DMZ-INTRANET -j ULOG --ulog-prefix "F0D:DMZ-INTRANET DROP"
-A DMZ-INTRANET -j DROP

-A INTRANET-INTERNET -j ULOG --ulog-prefix "F0D:INTRANET-INTERNET DROP"
-A INTRANET-INTERNET -j DROP

-A INTRANET-DMZ -j ULOG --ulog-prefix "F0D:INTRANET-DMZ DROP"
-A INTRANET-DMZ -j DROP

-A INTRANET-INTRANET -j ULOG --ulog-prefix "F0D:INTRANET-INTRANET DROP"
-A INTRANET-INTRANET -j DROP