Ajout : iodined tunnel IP sur DNS.
[lhc/ateliers.git] / etc / shorewall / rules
index f3e0c33..1798ad1 100644 (file)
@@ -7,10 +7,27 @@
 #SECTION RELATED
 SECTION NEW
 
+Ping(ACCEPT)                  dns    $FW
+Mosh(ACCEPT)                  dns    $FW
+SSH(ACCEPT)                   dns    $FW
+
+Ping(ACCEPT)                  $FW    dns
+
+ACCEPT                        $FW    net         icmp
+DNS(ACCEPT)                   $FW    net
+Git(ACCEPT)                   $FW    net
+HTTP(ACCEPT)                  $FW    net
+HTTPS(ACCEPT)                 $FW    net
+NTP(ACCEPT)                   $FW    net
+SMTP(ACCEPT)                  $FW    net
+SMTPS(ACCEPT)                 $FW    net
+SSH(ACCEPT)                   $FW    net
+
 DNS(ACCEPT)                   net    $FW
 Git(ACCEPT)                   net    $FW
 HTTP(ACCEPT)                  net    $FW
 HTTPS(ACCEPT)                 net    $FW
+Iodine(ACCEPT)                net    $FW
 Limit(IMAPS,5,60):info        net    $FW         tcp   imaps
 IMAPS(ACCEPT)                 net    $FW
 Fanout(ACCEPT)                net    $FW
@@ -23,13 +40,3 @@ SSH(ACCEPT)                   net    $FW
 Limit(SSH,10,60):info         net    $FW         tcp   ssh
 Submission(ACCEPT)            net    $FW
 Limit(Submission,10,60):info  net    $FW         tcp   submission
-
-ACCEPT                        $FW    net         icmp
-DNS(ACCEPT)                   $FW    net
-Git(ACCEPT)                   $FW    net
-HTTP(ACCEPT)                  $FW    net
-HTTPS(ACCEPT)                 $FW    net
-NTP(ACCEPT)                   $FW    net
-SMTP(ACCEPT)                  $FW    net
-SMTPS(ACCEPT)                 $FW    net
-SSH(ACCEPT)                   $FW    net