|
|
|
@ -10,17 +10,45 @@ table inet firewall { |
|
|
|
flags interval |
|
|
|
elements = { |
|
|
|
# Si l'on souhaite ajouter des ranges d'ip c'est ici |
|
|
|
193.48.225.1-193.48.225.9, |
|
|
|
193.48.225.224/27, |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
set dmz_allowed_tcp_in { |
|
|
|
type ipv4_addr . inet_service |
|
|
|
flags interval |
|
|
|
elements = { |
|
|
|
} |
|
|
|
} |
|
|
|
set dmz_allowed_tcp_out { |
|
|
|
type ipv4_addr . inet_service |
|
|
|
flags interval |
|
|
|
elements = { |
|
|
|
} |
|
|
|
} |
|
|
|
set dmz_allowed_udp_in { |
|
|
|
type ipv4_addr . inet_service |
|
|
|
flags interval |
|
|
|
elements = { |
|
|
|
} |
|
|
|
} |
|
|
|
set dmz_allowed_udp_out { |
|
|
|
type ipv4_addr . inet_service |
|
|
|
flags interval |
|
|
|
elements = { |
|
|
|
} |
|
|
|
} |
|
|
|
|
|
|
|
|
|
|
|
chain to_dmz { |
|
|
|
# DMZ, tout le monde entre |
|
|
|
accept; |
|
|
|
ip daddr . tcp dport @dmz_allowed_tcp_in accept; |
|
|
|
ip daddr . udp dport @dmz_allowed_udp_in accept; |
|
|
|
drop; |
|
|
|
} |
|
|
|
|
|
|
|
chain from_dmz { |
|
|
|
# DMZ, tout le monde sort |
|
|
|
ip saddr . tcp dport @dmz_allowed_tcp_out accept; |
|
|
|
ip saddr . udp dport @dmz_allowed_udp_out accept; |
|
|
|
} |
|
|
|
|
|
|
|
} |
|
|
|
|