summaryrefslogtreecommitdiffstats
path: root/etc/shorewall/rules
diff options
context:
space:
mode:
authorHolger Levsen <holger@layer-acht.org>2012-10-21 14:55:35 +0200
committerHolger Levsen <holger@layer-acht.org>2012-10-21 14:55:35 +0200
commit63b2dbce87c82b917cd5e0574f04d51f0cf52d4f (patch)
treec1774c227e5aa56010b7b7fa46c2dbdf4d5f1551 /etc/shorewall/rules
parentec412beda5d3fba47597cce64aa235ffff203c36 (diff)
downloadjenkins.debian.net-63b2dbce87c82b917cd5e0574f04d51f0cf52d4f.tar.xz
setup shorewall(6) and let squid cache files up to 50MB
Diffstat (limited to 'etc/shorewall/rules')
-rw-r--r--etc/shorewall/rules32
1 files changed, 32 insertions, 0 deletions
diff --git a/etc/shorewall/rules b/etc/shorewall/rules
new file mode 100644
index 00000000..db08726c
--- /dev/null
+++ b/etc/shorewall/rules
@@ -0,0 +1,32 @@
+#
+# Shorewall version 4.0 - Sample Rules File for one-interface configuration.
+# Copyright (C) 2006 by the Shorewall Team
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# See the file README.txt for further details.
+#------------------------------------------------------------------------------------------------------------
+# For information on entries in this file, type "man shorewall-rules"
+######################################################################################################################################################################################
+#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK CONNLIMIT TIME HEADERS SWITCH
+# PORT PORT(S) DEST LIMIT GROUP
+#SECTION ALL
+#SECTION ESTABLISHED
+#SECTION RELATED
+SECTION NEW
+
+# Drop Ping from the "bad" net zone.. and prevent your log from being flooded..
+
+Ping(DROP) net $FW
+
+# Permit all ICMP traffic FROM the firewall TO the net zone
+
+ACCEPT $FW net icmp
+
+# http and ssh are allowed
+ACCEPT net $FW tcp 80
+ACCEPT net $FW tcp 22
+