1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44
|
# -*- shell-script -*-
#
# Ferm example script
#
# Firewall configuration for a file server (NFSv4 and SMB).
#
# Author: Max Kellermann <max@duempel.org>
#
table filter {
chain INPUT {
policy DROP;
# connection tracking
mod state state INVALID DROP;
mod state state (ESTABLISHED RELATED) ACCEPT;
# allow local connections
interface lo ACCEPT;
# respond to ping
proto icmp icmp-type echo-request ACCEPT;
# remote administration
proto tcp dport ssh ACCEPT;
# samba
proto tcp dport (139 445) ACCEPT; #smbd
proto udp dport (137:138) ACCEPT; #nmbd
# NFSv4
proto tcp dport sunrpc ACCEPT;
proto (tcp udp) dport 2049 ACCEPT;
# reject the rest gracefully
REJECT;
}
# outgoing connections are not limited
chain OUTPUT policy ACCEPT;
# this is not a router
chain FORWARD policy DROP;
}
|