firewall: allow OUTPUT: DNS and MAIL.
allow OUTPUT: ssh if an ssh client is available.
This commit is contained in:
		
							parent
							
								
									a80107a596
								
							
						
					
					
						commit
						5a8b0b54fc
					
				
							
								
								
									
										27
									
								
								firewall
								
								
								
								
							
							
						
						
									
										27
									
								
								firewall
								
								
								
								
							|  | @ -185,18 +185,21 @@ fw_start() { | |||
| # | ||||
| #  #### ICMP reply (Ping) | ||||
| #  #$IPT -A OUTPUT -j ACCEPT -p icmp -o "${ILAN}" --icmp-type 0 -s "${IPLAN}" -d 0/0 -m state --state ESTABLISHED,RELATED -m comment --comment "ICMP reply" | ||||
| # | ||||
| #  #### SSH | ||||
| #  $IPT -A OUTPUT -j ACCEPT -p tcp -o "${ILAN}" --dport 22 -m state --state NEW -m comment --comment "New SSH out" | ||||
| # | ||||
| #  #### Mail (rapport d'erreur, ...) | ||||
| #  $IPT -A OUTPUT -j ACCEPT -p tcp -o "${ILAN}" --dport 25 -m state --state NEW -m comment --comment "SMTP out" | ||||
| #  $IPT -A OUTPUT -j ACCEPT -p tcp -o "${ILAN}" --dport 143 -m state --state NEW -m comment --comment "Imap" | ||||
| #  $IPT -A OUTPUT -j ACCEPT -p tcp -o "${ILAN}" --dport 993 -m state --state NEW -m comment --comment "Imaps" | ||||
| # | ||||
| #  #### DNS (résolution de noms de domaines, ... ...) | ||||
| #  $IPT -A OUTPUT -j ACCEPT -p udp -o ${ILAN} --dport 53 -m state --state NEW -m comment --comment "DNS out udp" | ||||
| #  $IPT -A OUTPUT -j ACCEPT -p tcp -o ${ILAN} --dport 53 -m state --state NEW -m comment --comment "DNS out tcp" | ||||
| 
 | ||||
| 
 | ||||
|   if [ $(command -v ssh) ]; then | ||||
|     #### SSH | ||||
|     $IPT -A OUTPUT -j ACCEPT -p tcp -o "${ILAN}" --dport 22 -m state --state NEW -m comment --comment "SSH out" | ||||
|   fi | ||||
| 
 | ||||
|   #### Mail (rapport d'erreur, ...) | ||||
|   $IPT -A OUTPUT -j ACCEPT -p tcp -o "${ILAN}" --dport 25 -m state --state NEW -m comment --comment "SMTP out" | ||||
|   $IPT -A OUTPUT -j ACCEPT -p tcp -o "${ILAN}" --dport 143 -m state --state NEW -m comment --comment "IMAP out" | ||||
|   $IPT -A OUTPUT -j ACCEPT -p tcp -o "${ILAN}" --dport 993 -m state --state NEW -m comment --comment "IMAPS out" | ||||
| 
 | ||||
|   #### DNS (résolution de noms de domaines, ... ...) | ||||
|   $IPT -A OUTPUT -j ACCEPT -p udp -o ${ILAN} --dport 53 -m state --state NEW -m comment --comment "DNS out udp" | ||||
|   $IPT -A OUTPUT -j ACCEPT -p tcp -o ${ILAN} --dport 53 -m state --state NEW -m comment --comment "DNS out tcp" | ||||
| 
 | ||||
|   if [ $(command -v dhclient) ]; then | ||||
|     #### DHCP | ||||
|  |  | |||
		Loading…
	
		Reference in New Issue