Sophie

Sophie

distrib > Mandriva > 2010.0 > i586 > media > contrib-release > by-pkgid > dca483b59ba61f3fa092de932ddd570e > files > 907

nuface-2.0.14-2mdv2009.1.i586.rpm

#Generated by nupyf on 2008-10-03 13:27:33.801625 from ./standard/acls_lan-to-fweth2.xml

#DISPATCH and DEFAULT Rules
:INTERNET-INTERNET -
:INTERNET-DMZ -
:INTERNET-INTRANET -
:DMZ-INTERNET -
:DMZ-DMZ -
:DMZ-INTRANET -
:INTRANET-INTERNET -
:INTRANET-DMZ -
:INTRANET-INTRANET -
:IF-INTERNET -
:INTERNET-IF -
:IF-DMZ -
:DMZ-IF -
:IF-INTRANET -
:INTRANET-IF -
-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A FORWARD -m state --state INVALID -j DROP
-A INPUT -m state --state INVALID -j DROP
-A OUTPUT -m state --state INVALID -j DROP

-A FORWARD -s 192.168.33.0/25 -d 192.168.33.0/25 -i eth1 -o eth1 -j DMZ-DMZ
-A FORWARD -s 192.168.33.0/25 -d 192.168.33.128/25 -i eth1 -o eth2 -j DMZ-INTRANET
-A FORWARD -s 192.168.33.128/25 -d 192.168.33.0/25 -i eth2 -o eth1 -j INTRANET-DMZ
-A FORWARD -s 192.168.33.128/25 -d 192.168.33.128/25 -i eth2 -o eth2 -j INTRANET-INTRANET
-A INPUT -s 192.168.33.0/25 -i eth1 -j DMZ-IF
-A INPUT -s 192.168.33.128/25 -i eth2 -j INTRANET-IF
-A OUTPUT -d 192.168.33.0/25 -o eth1 -j IF-DMZ
-A OUTPUT -d 192.168.33.128/25 -o eth2 -j IF-INTRANET
-A INPUT -i eth0 -j INTERNET-IF
-A OUTPUT -o eth0 -j IF-INTERNET
-A FORWARD -s 192.168.33.0/25 -i eth1 -o eth0 -j DMZ-INTERNET
-A FORWARD -s 192.168.33.128/25 -i eth2 -o eth0 -j INTRANET-INTERNET
-A FORWARD -d 192.168.33.0/25 -i eth0 -o eth1 -j INTERNET-DMZ
-A FORWARD -d 192.168.33.128/25 -i eth0 -o eth2 -j INTERNET-INTRANET
-A FORWARD -i eth0 -o eth0 -j INTERNET-INTERNET

-A INPUT -i lo -j ACCEPT
-A OUTPUT -o lo -j ACCEPT

-A FORWARD -j ULOG --ulog-prefix "DFT_FORWARD_DROP"
-A FORWARD -j DROP
-A INPUT -j ULOG --ulog-prefix "DFT_INPUT_DROP"
-A INPUT -j DROP
-A OUTPUT -j ULOG --ulog-prefix "DFT_OUTPUT_DROP"
-A OUTPUT -j DROP