Diff for scripts/shell/firewall/fw-universal.sh between version 2.39 and 2.41
version 2.39, 2006/02/28 17:50:00 |
version 2.41, 2006/03/04 02:43:23 |
|
|
#$IPTABLES -A FORWARD -m state --state NEW -o $NAT_LAN_IFACE -j ACCEPT |
#$IPTABLES -A FORWARD -m state --state NEW -o $NAT_LAN_IFACE -j ACCEPT |
$IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT |
$IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT |
|
|
|
# hide NAT clients behind firewall: - set TTL |
|
# XXX: warning: this breaks traceroute !!! |
|
if [ "e$NAT_SET_TTL" = "eyes" ]; then |
|
echo "NAT: clients hidden behind firewall - setting TTL" |
|
$IPTABLES -t mangle -A POSTROUTING -o $NAT_LAN_IFACE -j TTL --ttl-set 64 |
|
fi |
|
|
|
|
fi |
fi |
} # }}} |
} # }}} |
|
|
|
|
syn_flood |
syn_flood |
mangle_prerouting |
mangle_prerouting |
mangle_output |
mangle_output |
|
accept_related |
log_new_connections |
log_new_connections |
drop_output |
drop_output |
allow_input |
allow_input |
allow_output |
allow_output |
allow_icmp |
allow_icmp |
accept_related |
|
accept_loopback |
accept_loopback |
masquerade |
masquerade |
log_input_drop |
log_input_drop |
Platon Group <platon@platon.org> http://platon.org/
|
|