1
0
mirror of https://github.com/fwbuilder/fwbuilder synced 2026-03-18 17:27:20 +01:00

* PolicyCompiler_ipt.cpp (processNext): see #2402 "Tag action

should be done in PREROUTING so it can be acted on later". If a
rule has both tagging and classification options, the rule should
be split so that iptables command doing tagging goes in PREROUTING
and rule doing classification goes into POSTROUTING chain.
;
This commit is contained in:
Vadim Kurland 2011-05-13 18:21:56 -07:00
parent a787f35fd0
commit 6f9add86c3
134 changed files with 2871 additions and 579 deletions

View File

@ -1,5 +1,11 @@
2011-05-13 vadim <vadim@netcitadel.com>
* PolicyCompiler_ipt.cpp (processNext): see #2402 "Tag action
should be done in PREROUTING so it can be acted on later". If a
rule has both tagging and classification options, the rule should
be split so that iptables command doing tagging goes in PREROUTING
and rule doing classification goes into POSTROUTING chain.
* PolicyCompiler_ipt.cpp (processNext): see #2401 "Deprecating
Route option for iptables". This target is not included in any of
the popular Linux distributions (checked in Ubuntu, Fedora and

View File

@ -3233,7 +3233,9 @@ bool PolicyCompiler_ipt::decideOnChainIfLoopback::processNext()
}
/**
* target CLASSIFY is only valid in mangle table, chain POSTROUTING
* target CLASSIFY is only valid in mangle table, chain POSTROUTING.
* However if the same rule also has tagging option, it should be
* split because we want to tag in PREROUTING
*/
bool PolicyCompiler_ipt::decideOnChainForClassify::processNext()
{
@ -3247,7 +3249,22 @@ bool PolicyCompiler_ipt::decideOnChainForClassify::processNext()
}
if (rule->getStr("ipt_chain").empty())
ipt_comp->setChain(rule,"POSTROUTING");
{
if (rule->getTagging())
{
PolicyRule *r = compiler->dbcopy->createPolicyRule();
compiler->temp_ruleset->add(r);
r->duplicate(rule);
r->setClassification(false);
r->setRouting(false);
r->setAction(PolicyRule::Continue);
tmp_queue.push_back(r);
rule->setTagging(false);
}
ipt_comp->setChain(rule, "POSTROUTING");
}
tmp_queue.push_back(rule);
return true;

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:43 2011 PDT by vadim
# Generated Fri May 13 17:57:34 2011 PDT by vadim
#
# files: * cluster1_secuwall-1.fw /etc/cluster1_secuwall-1.fw
#
@ -588,7 +588,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:43 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:34 2011 by vadim"
log "Database was cluster-tests.fwb"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:55 2011 PDT by vadim
# Generated Fri May 13 17:56:45 2011 PDT by vadim
#
# files: * firewall-base-rulesets.fw /etc/fw/firewall-base-rulesets.fw
#
@ -445,7 +445,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:55 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:45 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:06 2011 PDT by vadim
# Generated Fri May 13 17:56:54 2011 PDT by vadim
#
# files: * firewall-ipv6-1.fw /etc/firewall-ipv6-1.fw
#
@ -702,7 +702,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:06 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:54 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:06 2011 PDT by vadim
# Generated Fri May 13 17:56:54 2011 PDT by vadim
#
# files: * firewall-ipv6-2.fw /etc/firewall-ipv6-2.fw
#
@ -966,7 +966,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:06 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:54 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:16 2011 PDT by vadim
# Generated Fri May 13 17:57:04 2011 PDT by vadim
#
# files: * firewall-ipv6-3.fw /etc/firewall-ipv6-3.fw
#
@ -596,7 +596,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:16 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:04 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:27 2011 PDT by vadim
# Generated Fri May 13 17:57:16 2011 PDT by vadim
#
# files: * firewall-ipv6-4-1.fw /etc/firewall-ipv6-4-1.fw
#
@ -545,7 +545,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:27 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:16 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:16 2011 PDT by vadim
# Generated Fri May 13 17:57:04 2011 PDT by vadim
#
# files: * firewall-ipv6-4.fw /etc/firewall-ipv6-4.fw
#
@ -581,7 +581,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:16 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:04 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:19 2011 PDT by vadim
# Generated Fri May 13 17:57:07 2011 PDT by vadim
#
# files: * firewall-ipv6-5.fw /etc/firewall-ipv6-5.fw
#
@ -412,7 +412,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:19 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:07 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:20 2011 PDT by vadim
# Generated Fri May 13 17:57:09 2011 PDT by vadim
#
# files: * firewall-ipv6-6.fw /etc/firewall-ipv6-6.fw
#
@ -399,7 +399,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:20 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:09 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:22 2011 PDT by vadim
# Generated Fri May 13 17:57:10 2011 PDT by vadim
#
# files: * firewall-ipv6-7.fw /etc/firewall-ipv6-7.fw
#
@ -443,7 +443,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:22 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:10 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:24 2011 PDT by vadim
# Generated Fri May 13 17:57:12 2011 PDT by vadim
#
# files: * firewall-ipv6-8.fw /etc/firewall-ipv6-8.fw
#
@ -484,7 +484,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:24 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:12 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:25 2011 PDT by vadim
# Generated Fri May 13 17:57:14 2011 PDT by vadim
#
# files: * firewall-ipv6-ipt-reset-prolog-after-flush.fw /etc/firewall-ipv6-ipt-reset-prolog-after-flush.fw
#
@ -442,7 +442,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:25 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:14 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:27 2011 PDT by vadim
# Generated Fri May 13 17:57:15 2011 PDT by vadim
#
# files: * firewall-ipv6-ipt-reset-prolog-after-interfaces.fw /etc/firewall-ipv6-ipt-reset-prolog-after-interfaces.fw
#
@ -442,7 +442,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:27 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:15 2011 by vadim"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:29 2011 PDT by vadim
# Generated Fri May 13 17:57:18 2011 PDT by vadim
#
# files: * firewall-ipv6-ipt-reset-prolog-top.fw /etc/firewall-ipv6-ipt-reset-prolog-top.fw
#
@ -442,7 +442,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:29 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:18 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:29 2011 PDT by vadim
# Generated Fri May 13 17:57:18 2011 PDT by vadim
#
# files: * firewall-ipv6-nd-ns-1.fw /etc/firewall-ipv6-nd-ns-1.fw
#
@ -442,7 +442,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:29 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:18 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:31 2011 PDT by vadim
# Generated Fri May 13 17:57:20 2011 PDT by vadim
#
# files: * firewall-ipv6-nd-ns-2.fw /etc/firewall-ipv6-nd-ns-2.fw
#
@ -446,7 +446,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:31 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:20 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:31 2011 PDT by vadim
# Generated Fri May 13 17:57:20 2011 PDT by vadim
#
# files: * firewall-ipv6-prolog-after-flush.fw /etc/firewall-ipv6-prolog-after-flush.fw
#
@ -420,7 +420,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:31 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:20 2011 by vadim"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:33 2011 PDT by vadim
# Generated Fri May 13 17:57:22 2011 PDT by vadim
#
# files: * firewall-ipv6-prolog-after-interfaces.fw /etc/firewall-ipv6-prolog-after-interfaces.fw
#
@ -420,7 +420,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:33 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:22 2011 by vadim"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:33 2011 PDT by vadim
# Generated Fri May 13 17:57:22 2011 PDT by vadim
#
# files: * firewall-ipv6-prolog-top.fw /etc/firewall-ipv6-prolog-top.fw
#
@ -420,7 +420,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:33 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:22 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:35 2011 PDT by vadim
# Generated Fri May 13 17:57:24 2011 PDT by vadim
#
# files: * firewall-server-1-s.fw /etc/fw/firewall-server-1-s.fw
#
@ -393,7 +393,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:35 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:24 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:08 2011 PDT by vadim
# Generated Fri May 13 17:54:48 2011 PDT by vadim
#
# files: * firewall.fw /etc/fw/firewall.fw
#
@ -1376,7 +1376,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:08 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:54:48 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:09 2011 PDT by vadim
# Generated Fri May 13 17:54:49 2011 PDT by vadim
#
# files: * firewall1.fw /etc/fw/firewall1.fw
#
@ -1248,7 +1248,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:09 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:54:49 2011 by vadim"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:09 2011 PDT by vadim
# Generated Fri May 13 17:54:50 2011 PDT by vadim
#
# files: * firewall10.fw /etc/fw/firewall10.fw
#
@ -473,7 +473,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:09 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:54:50 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:12 2011 PDT by vadim
# Generated Fri May 13 17:54:52 2011 PDT by vadim
#
# files: * firewall11.fw /etc/fw/firewall11.fw
#
@ -589,7 +589,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:12 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:54:52 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:12 2011 PDT by vadim
# Generated Fri May 13 17:54:52 2011 PDT by vadim
#
# files: * firewall12.fw /etc/fw/firewall12.fw
#
@ -511,7 +511,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:12 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:54:52 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:14 2011 PDT by vadim
# Generated Fri May 13 17:54:55 2011 PDT by vadim
#
# files: * firewall13.fw /etc/fw/firewall13.fw
#
@ -385,7 +385,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:14 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:54:55 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:14 2011 PDT by vadim
# Generated Fri May 13 17:54:55 2011 PDT by vadim
#
# files: * firewall14.fw /etc/fw/firewall14.fw
#
@ -404,7 +404,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:14 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:54:55 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:16 2011 PDT by vadim
# Generated Fri May 13 17:54:57 2011 PDT by vadim
#
# files: * firewall15.fw /etc/fw/firewall15.fw
#
@ -388,7 +388,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:16 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:54:57 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:16 2011 PDT by vadim
# Generated Fri May 13 17:54:57 2011 PDT by vadim
#
# files: * firewall16.fw /etc/fw/firewall16.fw
#
@ -492,7 +492,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:16 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:54:57 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:18 2011 PDT by vadim
# Generated Fri May 13 17:55:00 2011 PDT by vadim
#
# files: * firewall17.fw /etc/fw/firewall17.fw
#
@ -471,7 +471,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:18 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:00 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:19 2011 PDT by vadim
# Generated Fri May 13 17:55:00 2011 PDT by vadim
#
# files: * firewall18.fw /etc/fw/firewall18.fw
#
@ -504,7 +504,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:19 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:00 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:21 2011 PDT by vadim
# Generated Fri May 13 17:55:02 2011 PDT by vadim
#
# files: * firewall19.fw /etc/fw/firewall19.fw
#
@ -508,7 +508,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:21 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:02 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:28 2011 PDT by vadim
# Generated Fri May 13 17:55:10 2011 PDT by vadim
#
# files: * firewall2-1.fw /etc/fw/firewall2-1.fw
#
@ -1430,7 +1430,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:28 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:10 2011 by vadim"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:32 2011 PDT by vadim
# Generated Fri May 13 17:55:14 2011 PDT by vadim
#
# files: * firewall2-2.fw /etc/fw/firewall2-2.fw
#
@ -1259,7 +1259,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:32 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:14 2011 by vadim"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:33 2011 PDT by vadim
# Generated Fri May 13 17:55:15 2011 PDT by vadim
#
# files: * firewall2-3.fw /etc/fw/firewall2-3.fw
#
@ -1118,7 +1118,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:33 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:15 2011 by vadim"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:36 2011 PDT by vadim
# Generated Fri May 13 17:55:18 2011 PDT by vadim
#
# files: * firewall2-4.fw /etc/fw/firewall2-4.fw
#
@ -424,7 +424,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:36 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:18 2011 by vadim"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:38 2011 PDT by vadim
# Generated Fri May 13 17:55:20 2011 PDT by vadim
#
# files: * firewall2-5.fw /etc/fw/firewall2-5.fw
#
@ -455,7 +455,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:38 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:20 2011 by vadim"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:41 2011 PDT by vadim
# Generated Fri May 13 17:55:23 2011 PDT by vadim
#
# files: * firewall2-6.fw /etc/fw/firewall2-6.fw
#
@ -482,7 +482,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:41 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:23 2011 by vadim"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:43 2011 PDT by vadim
# Generated Fri May 13 17:55:25 2011 PDT by vadim
#
# files: * firewall2-7.fw /etc/fw/firewall2-7.fw
#
@ -424,7 +424,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:43 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:25 2011 by vadim"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:22 2011 PDT by vadim
# Generated Fri May 13 17:55:04 2011 PDT by vadim
#
# files: * firewall2.fw /etc/fw/firewall2.fw
#
@ -1482,7 +1482,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:22 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:04 2011 by vadim"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:25 2011 PDT by vadim
# Generated Fri May 13 17:55:06 2011 PDT by vadim
#
# files: * firewall20-ipv6.fw /etc/fw/firewall20-ipv6.fw
#
@ -456,7 +456,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:25 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:06 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:22 2011 PDT by vadim
# Generated Fri May 13 17:55:04 2011 PDT by vadim
#
# files: * firewall20.fw /etc/fw/firewall20.fw
#
@ -674,7 +674,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:22 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:04 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:27 2011 PDT by vadim
# Generated Fri May 13 17:55:09 2011 PDT by vadim
#
# files: * firewall21-1.fw /etc/fw/firewall21-1.fw
#
@ -470,7 +470,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:27 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:09 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:25 2011 PDT by vadim
# Generated Fri May 13 17:55:06 2011 PDT by vadim
#
# files: * firewall21.fw /etc/fw/firewall21.fw
#
@ -469,7 +469,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:25 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:06 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:29 2011 PDT by vadim
# Generated Fri May 13 17:55:10 2011 PDT by vadim
#
# files: * firewall22.fw /etc/fw/firewall22.fw
#
@ -390,7 +390,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:29 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:10 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:34 2011 PDT by vadim
# Generated Fri May 13 17:55:16 2011 PDT by vadim
#
# files: * firewall23-1.fw /etc/fw/firewall23-1.fw
#
@ -564,7 +564,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:34 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:16 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:31 2011 PDT by vadim
# Generated Fri May 13 17:55:13 2011 PDT by vadim
#
# files: * firewall23.fw /etc/fw/firewall23.fw
#
@ -476,7 +476,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:31 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:13 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:36 2011 PDT by vadim
# Generated Fri May 13 17:55:18 2011 PDT by vadim
#
# files: * firewall24.fw /etc/fw/firewall24.fw
#
@ -493,7 +493,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:36 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:18 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:38 2011 PDT by vadim
# Generated Fri May 13 17:55:20 2011 PDT by vadim
#
# files: * firewall25.fw /etc/fw/firewall25.fw
#
@ -684,7 +684,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:38 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:20 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:41 2011 PDT by vadim
# Generated Fri May 13 17:55:22 2011 PDT by vadim
#
# files: * firewall26.fw /etc/fw/firewall26.fw
#
@ -562,7 +562,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:41 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:22 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:43 2011 PDT by vadim
# Generated Fri May 13 17:55:25 2011 PDT by vadim
#
# files: * firewall27.fw /etc/fw/firewall27.fw
#
@ -546,7 +546,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:43 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:25 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:46 2011 PDT by vadim
# Generated Fri May 13 17:55:27 2011 PDT by vadim
#
# files: * firewall28.fw /etc/fw/firewall28.fw
#
@ -409,7 +409,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:46 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:27 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:46 2011 PDT by vadim
# Generated Fri May 13 17:55:28 2011 PDT by vadim
#
# files: * firewall29.fw /etc/fw/firewall29.fw
#
@ -440,7 +440,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:46 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:28 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:48 2011 PDT by vadim
# Generated Fri May 13 17:55:30 2011 PDT by vadim
#
# files: * firewall3.fw /etc/fw/firewall3.fw
#
@ -578,7 +578,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:48 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:30 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:48 2011 PDT by vadim
# Generated Fri May 13 17:55:30 2011 PDT by vadim
#
# files: * firewall30.fw /etc/fw/firewall30.fw
#
@ -375,7 +375,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:48 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:30 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:51 2011 PDT by vadim
# Generated Fri May 13 17:55:32 2011 PDT by vadim
#
# files: * firewall31.fw /etc/fw/firewall31.fw
#
@ -445,7 +445,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:51 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:32 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:51 2011 PDT by vadim
# Generated Fri May 13 17:55:32 2011 PDT by vadim
#
# files: * firewall32.fw /etc/fw/firewall32.fw
#
@ -416,7 +416,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:51 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:32 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:59 2011 PDT by vadim
# Generated Fri May 13 17:55:41 2011 PDT by vadim
#
# files: * firewall33-1.fw /etc/fw/firewall33-1.fw
#
@ -395,12 +395,11 @@ script_body() {
#
$IPTABLES -N Cid438728A918346.0
$IPTABLES -A Policy -m state --state NEW -j Cid438728A918346.0
$IPTABLES -A Cid438728A918346.0 -d 74.125.153.99 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.153.103 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.153.104 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.153.105 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.153.106 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.153.147 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.224.48 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.224.49 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.224.50 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.224.51 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.224.52 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 157.166.224.25 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 157.166.224.26 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 157.166.226.25 -j RETURN
@ -526,7 +525,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:59 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:41 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:10:59 2011 PDT by vadim
# Generated Fri May 13 17:55:41 2011 PDT by vadim
#
# files: * firewall33.fw /etc/fw/firewall33.fw
#
@ -443,12 +443,11 @@ script_body() {
$IPTABLES -A OUTPUT -m state --state NEW -j Cid438728A918346.0
$IPTABLES -A INPUT -m state --state NEW -j Cid438728A918346.0
$IPTABLES -A FORWARD -m state --state NEW -j Cid438728A918346.0
$IPTABLES -A Cid438728A918346.0 -d 74.125.153.99 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.153.103 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.153.104 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.153.105 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.153.106 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.153.147 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.224.48 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.224.49 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.224.50 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.224.51 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 74.125.224.52 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 157.166.224.25 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 157.166.224.26 -j RETURN
$IPTABLES -A Cid438728A918346.0 -d 157.166.226.25 -j RETURN
@ -573,7 +572,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:10:59 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:41 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:01 2011 PDT by vadim
# Generated Fri May 13 17:55:44 2011 PDT by vadim
#
# files: * firewall34.fw /etc/fw/firewall34.fw
#
@ -648,7 +648,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:01 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:44 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:01 2011 PDT by vadim
# Generated Fri May 13 17:55:44 2011 PDT by vadim
#
# files: * firewall35.fw /etc/fw/firewall35.fw
#
@ -540,7 +540,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:01 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:44 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:04 2011 PDT by vadim
# Generated Fri May 13 17:55:47 2011 PDT by vadim
#
# files: * firewall36-1.fw /etc/firewall36-1.fw
#
@ -433,7 +433,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:04 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:47 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:06 2011 PDT by vadim
# Generated Fri May 13 17:55:49 2011 PDT by vadim
#
# files: * firewall36-2.fw /etc/firewall36-2.fw
#
@ -433,7 +433,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:06 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:49 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,25 +4,16 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:04 2011 PDT by vadim
# Generated Fri May 13 17:55:47 2011 PDT by vadim
#
# files: * firewall36.fw /etc/firewall36.fw
#
# Compiled for iptables (any version)
#
# testing routing rules - both actually routing and ROUTE target
# testing routing rules
# routing ruleset installs ECMP default
# firewall36:Policy:1: error: Option Route is deprecated. You can use Custom Action to geenrate iptables command using '-j ROUTE' target if it is supported by your firewall OS
# firewall36:Policy:2: error: Option Route is deprecated. You can use Custom Action to geenrate iptables command using '-j ROUTE' target if it is supported by your firewall OS
# firewall36:Policy:3: error: Option Route is deprecated. You can use Custom Action to geenrate iptables command using '-j ROUTE' target if it is supported by your firewall OS
# firewall36:Policy:4: error: Option Route is deprecated. You can use Custom Action to geenrate iptables command using '-j ROUTE' target if it is supported by your firewall OS
# firewall36:Policy:5: error: Option Route is deprecated. You can use Custom Action to geenrate iptables command using '-j ROUTE' target if it is supported by your firewall OS
# firewall36:Policy:1: error: Option Route is deprecated. You can use Custom Action to geenrate iptables command using '-j ROUTE' target if it is supported by your firewall OS
# firewall36:Policy:4: error: Option Route is deprecated. You can use Custom Action to geenrate iptables command using '-j ROUTE' target if it is supported by your firewall OS
# firewall36:Policy:5: error: Option Route is deprecated. You can use Custom Action to geenrate iptables command using '-j ROUTE' target if it is supported by your firewall OS
# ROUTE target is deprecated in 4.3.0
# firewall36:Routing:4: warning: Rule has been suppressed because it contains IPv6 objects and Firewall Builder does not support IPv6 routing rules at this time
@ -322,28 +313,7 @@ script_body() {
# ================ Table 'filter', rule set Policy
#
# Rule 0 (global)
#
echo "Rule 0 (global)"
#
# This permits access from internal net
# to the Internet and DMZ
$IPTABLES -A INPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
$IPTABLES -A OUTPUT -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
$IPTABLES -A FORWARD -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
#
# Rule 6 (global)
#
echo "Rule 6 (global)"
#
$IPTABLES -N RULE_6
$IPTABLES -A OUTPUT -j RULE_6
$IPTABLES -A INPUT -j RULE_6
$IPTABLES -A FORWARD -j RULE_6
$IPTABLES -A RULE_6 -j LOG --log-level info --log-prefix "RULE 6 -- DENY "
$IPTABLES -A RULE_6 -j DROP
@ -527,7 +497,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:04 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:47 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:08 2011 PDT by vadim
# Generated Fri May 13 17:55:51 2011 PDT by vadim
#
# files: * firewall37-1.fw /etc/fw/firewall37-1.fw
#
@ -966,7 +966,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:08 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:51 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

680
test/ipt/firewall37-2.fw.orig Executable file
View File

@ -0,0 +1,680 @@
#!/bin/sh
#
# This is automatically generated file. DO NOT MODIFY !
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 18:10:31 2011 PDT by vadim
#
# files: * firewall37-2.fw /etc/fw/firewall37-2.fw
#
# Compiled for iptables (any version)
#
# testing TAG and CLASSIFY rules and combinations
# normal script mode (not using iptables-restore)
FWBDEBUG=""
PATH="/sbin:/usr/sbin:/bin:/usr/bin:${PATH}"
export PATH
LSMOD="/sbin/lsmod"
MODPROBE="/sbin/modprobe"
IPTABLES="/sbin/iptables"
IP6TABLES="/sbin/ip6tables"
IPTABLES_RESTORE="/sbin/iptables-restore"
IP6TABLES_RESTORE="/sbin/ip6tables-restore"
IP="/sbin/ip"
IFCONFIG="/sbin/ifconfig"
VCONFIG="/sbin/vconfig"
BRCTL="/sbin/brctl"
IFENSLAVE="/sbin/ifenslave"
IPSET="/usr/sbin/ipset"
LOGGER="/usr/bin/logger"
log() {
echo "$1"
command -v "$LOGGER" >/dev/null 2>&1 && $LOGGER -p info "$1"
}
getInterfaceVarName() {
echo $1 | sed 's/\./_/'
}
getaddr_internal() {
dev=$1
name=$2
af=$3
L=$($IP $af addr show dev $dev | sed -n '/inet/{s!.*inet6* !!;s!/.*!!p}' | sed 's/peer.*//')
test -z "$L" && {
eval "$name=''"
return
}
eval "${name}_list=\"$L\""
}
getaddr() {
getaddr_internal $1 $2 "-4"
}
getaddr6() {
getaddr_internal $1 $2 "-6"
}
# function getinterfaces is used to process wildcard interfaces
getinterfaces() {
NAME=$1
$IP link show | grep ": $NAME" | while read L; do
OIFS=$IFS
IFS=" :"
set $L
IFS=$OIFS
echo $2
done
}
diff_intf() {
func=$1
list1=$2
list2=$3
cmd=$4
for intf in $list1
do
echo $list2 | grep -q $intf || {
# $vlan is absent in list 2
$func $intf $cmd
}
done
}
find_program() {
PGM=$1
command -v $PGM >/dev/null 2>&1 || {
echo "$PGM not found"
exit 1
}
}
check_tools() {
find_program $IPTABLES
find_program $MODPROBE
find_program $IP
}
reset_iptables_v4() {
$IPTABLES -P OUTPUT DROP
$IPTABLES -P INPUT DROP
$IPTABLES -P FORWARD DROP
cat /proc/net/ip_tables_names | while read table; do
$IPTABLES -t $table -L -n | while read c chain rest; do
if test "X$c" = "XChain" ; then
$IPTABLES -t $table -F $chain
fi
done
$IPTABLES -t $table -X
done
}
reset_iptables_v6() {
$IP6TABLES -P OUTPUT DROP
$IP6TABLES -P INPUT DROP
$IP6TABLES -P FORWARD DROP
cat /proc/net/ip6_tables_names | while read table; do
$IP6TABLES -t $table -L -n | while read c chain rest; do
if test "X$c" = "XChain" ; then
$IP6TABLES -t $table -F $chain
fi
done
$IP6TABLES -t $table -X
done
}
P2P_INTERFACE_WARNING=""
missing_address() {
address=$1
cmd=$2
oldIFS=$IFS
IFS="@"
set $address
addr=$1
interface=$2
IFS=$oldIFS
$IP addr show dev $interface | grep -q POINTOPOINT && {
test -z "$P2P_INTERFACE_WARNING" && echo "Warning: Can not update address of interface $interface. fwbuilder can not manage addresses of point-to-point interfaces yet"
P2P_INTERFACE_WARNING="yes"
return
}
test "$cmd" = "add" && {
echo "# Adding ip address: $interface $addr"
echo $addr | grep -q ':' && {
$FWBDEBUG $IP addr $cmd $addr dev $interface
} || {
$FWBDEBUG $IP addr $cmd $addr broadcast + dev $interface
}
}
test "$cmd" = "del" && {
echo "# Removing ip address: $interface $addr"
$FWBDEBUG $IP addr $cmd $addr dev $interface || exit 1
}
$FWBDEBUG $IP link set $interface up
}
list_addresses_by_scope() {
interface=$1
scope=$2
ignore_list=$3
$IP addr ls dev $interface | \
awk -v IGNORED="$ignore_list" -v SCOPE="$scope" \
'BEGIN {
split(IGNORED,ignored_arr);
for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
}
(/inet |inet6 / && $0 ~ SCOPE && !($2 in ignored_dict)) {print $2;}' | \
while read addr; do
echo "${addr}@$interface"
done | sort
}
update_addresses_of_interface() {
ignore_list=$2
set $1
interface=$1
shift
FWB_ADDRS=$(
for addr in $*; do
echo "${addr}@$interface"
done | sort
)
CURRENT_ADDRS_ALL_SCOPES=""
CURRENT_ADDRS_GLOBAL_SCOPE=""
$IP link show dev $interface >/dev/null 2>&1 && {
CURRENT_ADDRS_ALL_SCOPES=$(list_addresses_by_scope $interface 'scope .*' "$ignore_list")
CURRENT_ADDRS_GLOBAL_SCOPE=$(list_addresses_by_scope $interface 'scope global' "$ignore_list")
} || {
echo "# Interface $interface does not exist"
# Stop the script if we are not in test mode
test -z "$FWBDEBUG" && exit 1
}
diff_intf missing_address "$FWB_ADDRS" "$CURRENT_ADDRS_ALL_SCOPES" add
diff_intf missing_address "$CURRENT_ADDRS_GLOBAL_SCOPE" "$FWB_ADDRS" del
}
clear_addresses_except_known_interfaces() {
$IP link show | sed 's/://g' | awk -v IGNORED="$*" \
'BEGIN {
split(IGNORED,ignored_arr);
for (a in ignored_arr) {ignored_dict[ignored_arr[a]]=1;}
}
(/state/ && !($2 in ignored_dict)) {print $2;}' | \
while read intf; do
echo "# Removing addresses not configured in fwbuilder from interface $intf"
$FWBDEBUG $IP addr flush dev $intf scope global
$FWBDEBUG $IP link set $intf down
done
}
check_file() {
test -r "$2" || {
echo "Can not find file $2 referenced by address table object $1"
exit 1
}
}
check_run_time_address_table_files() {
:
}
load_modules() {
:
OPTS=$1
MODULES_DIR="/lib/modules/`uname -r`/kernel/net/"
MODULES=$(find $MODULES_DIR -name '*conntrack*' \! -name '*ipv6*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')
echo $OPTS | grep -q nat && {
MODULES="$MODULES $(find $MODULES_DIR -name '*nat*'|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
}
echo $OPTS | grep -q ipv6 && {
MODULES="$MODULES $(find $MODULES_DIR -name nf_conntrack_ipv6|sed -e 's/^.*\///' -e 's/\([^\.]\)\..*/\1/')"
}
for module in $MODULES; do
if $LSMOD | grep ${module} >/dev/null; then continue; fi
$MODPROBE ${module} || exit 1
done
}
verify_interfaces() {
:
}
prolog_commands() {
echo "Running prolog script"
}
epilog_commands() {
echo "Running epilog script"
}
run_epilog_and_exit() {
epilog_commands
exit $1
}
configure_interfaces() {
:
# Configure interfaces
update_addresses_of_interface "eth0 192.168.1.22/24" ""
update_addresses_of_interface "eth1 22.22.23.22/24" ""
update_addresses_of_interface "eth2 192.168.2.1/24" ""
}
script_body() {
echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
echo 1800 > /proc/sys/net/ipv4/tcp_keepalive_intvl
# ================ IPv4
# ================ Table 'filter', automatic rules
# accept established sessions
$IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
# ================ Table 'mangle', rule set Policy
#
# Rule 0 (eth0)
#
echo "Rule 0 (eth0)"
#
$IPTABLES -t mangle -A PREROUTING -i eth0 -s 192.168.1.0/24 -j MARK --set-mark 2
$IPTABLES -t mangle -A POSTROUTING -i eth0 -s 192.168.1.0/24 -j CLASSIFY --set-class 1:2
#
# Rule 1 (eth0)
#
echo "Rule 1 (eth0)"
#
$IPTABLES -t mangle -A PREROUTING -i eth0 -s 192.168.1.0/24 -m state --state NEW -j MARK --set-mark 2
$IPTABLES -t mangle -A POSTROUTING -i eth0 -s 192.168.1.0/24 -m state --state NEW -j CLASSIFY --set-class 1:2
#
# Rule 2 (eth0)
#
echo "Rule 2 (eth0)"
#
$IPTABLES -t mangle -A PREROUTING -i eth0 -s 192.168.1.0/24 -m state --state NEW -j MARK --set-mark 2
$IPTABLES -t mangle -A POSTROUTING -i eth0 -s 192.168.1.0/24 -m state --state NEW -j CLASSIFY --set-class 1:2
#
# Rule 3 (eth0)
#
echo "Rule 3 (eth0)"
#
$IPTABLES -t mangle -A PREROUTING -i eth0 -s 192.168.1.0/24 -j MARK --set-mark 2
$IPTABLES -t mangle -A POSTROUTING -i eth0 -s 192.168.1.0/24 -j CLASSIFY --set-class 1:2
#
# Rule 4 (eth0)
#
echo "Rule 4 (eth0)"
#
$IPTABLES -t mangle -A PREROUTING -i eth0 -s ! 192.168.1.0/24 -j MARK --set-mark 2
$IPTABLES -t mangle -A POSTROUTING -i eth0 -s ! 192.168.1.0/24 -j CLASSIFY --set-class 1:2
#
# Rule 5 (eth0)
#
echo "Rule 5 (eth0)"
#
$IPTABLES -t mangle -A PREROUTING -i eth0 -s ! 192.168.1.0/24 -m state --state NEW -j MARK --set-mark 2
$IPTABLES -t mangle -A POSTROUTING -i eth0 -s ! 192.168.1.0/24 -m state --state NEW -j CLASSIFY --set-class 1:2
#
# Rule 6 (eth0)
#
echo "Rule 6 (eth0)"
#
$IPTABLES -t mangle -A PREROUTING -i eth0 -s ! 192.168.1.0/24 -m state --state NEW -j MARK --set-mark 2
$IPTABLES -t mangle -A POSTROUTING -i eth0 -s ! 192.168.1.0/24 -m state --state NEW -j CLASSIFY --set-class 1:2
#
# Rule 7 (eth0)
#
echo "Rule 7 (eth0)"
#
$IPTABLES -t mangle -A PREROUTING -i eth0 -s ! 192.168.1.0/24 -j MARK --set-mark 2
$IPTABLES -t mangle -A POSTROUTING -i eth0 -s ! 192.168.1.0/24 -j CLASSIFY --set-class 1:2
#
# Rule 8 (eth0)
#
echo "Rule 8 (eth0)"
#
$IPTABLES -N Cid591898X26049.0 -t mangle
$IPTABLES -t mangle -A PREROUTING -i eth0 -j Cid591898X26049.0
$IPTABLES -t mangle -A Cid591898X26049.0 -s 192.168.1.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591898X26049.0 -s 192.168.2.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591898X26049.0 -j MARK --set-mark 2
$IPTABLES -N Cid591898X26049.1 -t mangle
$IPTABLES -t mangle -A POSTROUTING -i eth0 -j Cid591898X26049.1
$IPTABLES -t mangle -A Cid591898X26049.1 -s 192.168.1.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591898X26049.1 -s 192.168.2.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591898X26049.1 -j CLASSIFY --set-class 1:2
#
# Rule 9 (eth0)
#
echo "Rule 9 (eth0)"
#
$IPTABLES -N Cid591842X26049.0 -t mangle
$IPTABLES -t mangle -A PREROUTING -i eth0 -m state --state NEW -j Cid591842X26049.0
$IPTABLES -t mangle -A Cid591842X26049.0 -s 192.168.1.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591842X26049.0 -s 192.168.2.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591842X26049.0 -j MARK --set-mark 2
$IPTABLES -N Cid591842X26049.1 -t mangle
$IPTABLES -t mangle -A POSTROUTING -i eth0 -m state --state NEW -j Cid591842X26049.1
$IPTABLES -t mangle -A Cid591842X26049.1 -s 192.168.1.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591842X26049.1 -s 192.168.2.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591842X26049.1 -j CLASSIFY --set-class 1:2
#
# Rule 10 (eth0)
#
echo "Rule 10 (eth0)"
#
$IPTABLES -N Cid591786X26049.0 -t mangle
$IPTABLES -t mangle -A PREROUTING -i eth0 -m state --state NEW -j Cid591786X26049.0
$IPTABLES -t mangle -A Cid591786X26049.0 -s 192.168.1.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591786X26049.0 -s 192.168.2.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591786X26049.0 -j MARK --set-mark 2
$IPTABLES -N Cid591786X26049.1 -t mangle
$IPTABLES -t mangle -A POSTROUTING -i eth0 -m state --state NEW -j Cid591786X26049.1
$IPTABLES -t mangle -A Cid591786X26049.1 -s 192.168.1.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591786X26049.1 -s 192.168.2.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591786X26049.1 -j CLASSIFY --set-class 1:2
#
# Rule 11 (eth0)
#
echo "Rule 11 (eth0)"
#
$IPTABLES -N Cid591730X26049.0 -t mangle
$IPTABLES -t mangle -A PREROUTING -i eth0 -j Cid591730X26049.0
$IPTABLES -t mangle -A Cid591730X26049.0 -s 192.168.1.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591730X26049.0 -s 192.168.2.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591730X26049.0 -j MARK --set-mark 2
$IPTABLES -N Cid591730X26049.1 -t mangle
$IPTABLES -t mangle -A POSTROUTING -i eth0 -j Cid591730X26049.1
$IPTABLES -t mangle -A Cid591730X26049.1 -s 192.168.1.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591730X26049.1 -s 192.168.2.0/24 -j RETURN
$IPTABLES -t mangle -A Cid591730X26049.1 -j CLASSIFY --set-class 1:2
#
# Rule 12 (eth0)
#
echo "Rule 12 (eth0)"
#
$IPTABLES -N Cid994929X26049.0 -t mangle
$IPTABLES -t mangle -A PREROUTING -i eth0 -s 192.168.1.0/24 -j Cid994929X26049.0
$IPTABLES -t mangle -A Cid994929X26049.0 -p icmp -m icmp --icmp-type 8/0 -j MARK --set-mark 2
$IPTABLES -t mangle -A Cid994929X26049.0 -p tcp -m tcp --dport 80 -j MARK --set-mark 2
$IPTABLES -N Cid994929X26049.1 -t mangle
$IPTABLES -t mangle -A POSTROUTING -i eth0 -s 192.168.1.0/24 -j Cid994929X26049.1
$IPTABLES -t mangle -A Cid994929X26049.1 -p icmp -m icmp --icmp-type 8/0 -j CLASSIFY --set-class 1:2
$IPTABLES -t mangle -A Cid994929X26049.1 -p tcp -m tcp --dport 80 -j CLASSIFY --set-class 1:2
#
# Rule 13 (eth0)
#
echo "Rule 13 (eth0)"
#
$IPTABLES -N Cid994873X26049.0 -t mangle
$IPTABLES -t mangle -A PREROUTING -i eth0 -s 192.168.1.0/24 -m state --state NEW -j Cid994873X26049.0
$IPTABLES -t mangle -A Cid994873X26049.0 -p icmp -m icmp --icmp-type 8/0 -j MARK --set-mark 2
$IPTABLES -t mangle -A Cid994873X26049.0 -p tcp -m tcp --dport 80 -j MARK --set-mark 2
$IPTABLES -N Cid994873X26049.1 -t mangle
$IPTABLES -t mangle -A POSTROUTING -i eth0 -s 192.168.1.0/24 -m state --state NEW -j Cid994873X26049.1
$IPTABLES -t mangle -A Cid994873X26049.1 -p icmp -m icmp --icmp-type 8/0 -j CLASSIFY --set-class 1:2
$IPTABLES -t mangle -A Cid994873X26049.1 -p tcp -m tcp --dport 80 -j CLASSIFY --set-class 1:2
#
# Rule 14 (eth0)
#
echo "Rule 14 (eth0)"
#
$IPTABLES -N Cid994817X26049.0 -t mangle
$IPTABLES -t mangle -A PREROUTING -i eth0 -s 192.168.1.0/24 -m state --state NEW -j Cid994817X26049.0
$IPTABLES -t mangle -A Cid994817X26049.0 -p icmp -m icmp --icmp-type 8/0 -j MARK --set-mark 2
$IPTABLES -t mangle -A Cid994817X26049.0 -p tcp -m tcp --dport 80 -j MARK --set-mark 2
$IPTABLES -N Cid994817X26049.1 -t mangle
$IPTABLES -t mangle -A POSTROUTING -i eth0 -s 192.168.1.0/24 -m state --state NEW -j Cid994817X26049.1
$IPTABLES -t mangle -A Cid994817X26049.1 -p icmp -m icmp --icmp-type 8/0 -j CLASSIFY --set-class 1:2
$IPTABLES -t mangle -A Cid994817X26049.1 -p tcp -m tcp --dport 80 -j CLASSIFY --set-class 1:2
#
# Rule 15 (eth0)
#
echo "Rule 15 (eth0)"
#
$IPTABLES -N Cid994761X26049.0 -t mangle
$IPTABLES -t mangle -A PREROUTING -i eth0 -s 192.168.1.0/24 -j Cid994761X26049.0
$IPTABLES -t mangle -A Cid994761X26049.0 -p icmp -m icmp --icmp-type 8/0 -j MARK --set-mark 2
$IPTABLES -t mangle -A Cid994761X26049.0 -p tcp -m tcp --dport 80 -j MARK --set-mark 2
$IPTABLES -N Cid994761X26049.1 -t mangle
$IPTABLES -t mangle -A POSTROUTING -i eth0 -s 192.168.1.0/24 -j Cid994761X26049.1
$IPTABLES -t mangle -A Cid994761X26049.1 -p icmp -m icmp --icmp-type 8/0 -j CLASSIFY --set-class 1:2
$IPTABLES -t mangle -A Cid994761X26049.1 -p tcp -m tcp --dport 80 -j CLASSIFY --set-class 1:2
# ================ Table 'filter', rule set Policy
#
# Rule 1 (eth0)
#
echo "Rule 1 (eth0)"
#
$IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
$IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j ACCEPT
#
# Rule 3 (eth0)
#
echo "Rule 3 (eth0)"
#
$IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -j ACCEPT
$IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -j ACCEPT
#
# Rule 5 (eth0)
#
echo "Rule 5 (eth0)"
#
$IPTABLES -A INPUT -i eth0 -s ! 192.168.1.0/24 -m state --state NEW -j ACCEPT
$IPTABLES -A FORWARD -i eth0 -s ! 192.168.1.0/24 -m state --state NEW -j ACCEPT
#
# Rule 7 (eth0)
#
echo "Rule 7 (eth0)"
#
$IPTABLES -A INPUT -i eth0 -s ! 192.168.1.0/24 -j ACCEPT
$IPTABLES -A FORWARD -i eth0 -s ! 192.168.1.0/24 -j ACCEPT
#
# Rule 9 (eth0)
#
echo "Rule 9 (eth0)"
#
$IPTABLES -N Cid591842X26049.0
$IPTABLES -A INPUT -i eth0 -m state --state NEW -j Cid591842X26049.0
$IPTABLES -A FORWARD -i eth0 -m state --state NEW -j Cid591842X26049.0
$IPTABLES -A Cid591842X26049.0 -s 192.168.1.0/24 -j RETURN
$IPTABLES -A Cid591842X26049.0 -s 192.168.2.0/24 -j RETURN
$IPTABLES -A Cid591842X26049.0 -j ACCEPT
#
# Rule 11 (eth0)
#
echo "Rule 11 (eth0)"
#
$IPTABLES -N Cid591730X26049.0
$IPTABLES -A INPUT -i eth0 -j Cid591730X26049.0
$IPTABLES -A FORWARD -i eth0 -j Cid591730X26049.0
$IPTABLES -A Cid591730X26049.0 -s 192.168.1.0/24 -j RETURN
$IPTABLES -A Cid591730X26049.0 -s 192.168.2.0/24 -j RETURN
$IPTABLES -A Cid591730X26049.0 -j ACCEPT
#
# Rule 13 (eth0)
#
echo "Rule 13 (eth0)"
#
$IPTABLES -N Cid994873X26049.0
$IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -m state --state NEW -j Cid994873X26049.0
$IPTABLES -A Cid994873X26049.0 -p icmp -m icmp --icmp-type 8/0 -j ACCEPT
$IPTABLES -A Cid994873X26049.0 -p tcp -m tcp --dport 80 -j ACCEPT
$IPTABLES -N Cid994873X26049.1
$IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -m state --state NEW -j Cid994873X26049.1
$IPTABLES -A Cid994873X26049.1 -p icmp -m icmp --icmp-type 8/0 -j ACCEPT
$IPTABLES -A Cid994873X26049.1 -p tcp -m tcp --dport 80 -j ACCEPT
#
# Rule 15 (eth0)
#
echo "Rule 15 (eth0)"
#
$IPTABLES -N Cid994761X26049.0
$IPTABLES -A INPUT -i eth0 -s 192.168.1.0/24 -j Cid994761X26049.0
$IPTABLES -A Cid994761X26049.0 -p icmp -m icmp --icmp-type 8/0 -j ACCEPT
$IPTABLES -A Cid994761X26049.0 -p tcp -m tcp --dport 80 -j ACCEPT
$IPTABLES -N Cid994761X26049.1
$IPTABLES -A FORWARD -i eth0 -s 192.168.1.0/24 -j Cid994761X26049.1
$IPTABLES -A Cid994761X26049.1 -p icmp -m icmp --icmp-type 8/0 -j ACCEPT
$IPTABLES -A Cid994761X26049.1 -p tcp -m tcp --dport 80 -j ACCEPT
#
# Rule 16 (global)
#
echo "Rule 16 (global)"
#
$IPTABLES -N RULE_16
$IPTABLES -A OUTPUT -j RULE_16
$IPTABLES -A INPUT -j RULE_16
$IPTABLES -A FORWARD -j RULE_16
$IPTABLES -A RULE_16 -j LOG --log-level info --log-prefix "RULE 16 -- DENY "
$IPTABLES -A RULE_16 -j DROP
}
ip_forward() {
:
}
reset_all() {
:
reset_iptables_v4
}
block_action() {
reset_all
}
stop_action() {
reset_all
$IPTABLES -P OUTPUT ACCEPT
$IPTABLES -P INPUT ACCEPT
$IPTABLES -P FORWARD ACCEPT
}
check_iptables() {
IP_TABLES="$1"
[ ! -e $IP_TABLES ] && return 151
NF_TABLES=$(cat $IP_TABLES 2>/dev/null)
[ -z "$NF_TABLES" ] && return 152
return 0
}
status_action() {
check_iptables "/proc/net/ip_tables_names"
ret_ipv4=$?
check_iptables "/proc/net/ip6_tables_names"
ret_ipv6=$?
[ $ret_ipv4 -eq 0 -o $ret_ipv6 -eq 0 ] && return 0
[ $ret_ipv4 -eq 151 -o $ret_ipv6 -eq 151 ] && {
echo "iptables modules are not loaded"
}
[ $ret_ipv4 -eq 152 -o $ret_ipv6 -eq 152 ] && {
echo "Firewall is not configured"
}
exit 3
}
# See how we were called.
# For backwards compatibility missing argument is equivalent to 'start'
cmd=$1
test -z "$cmd" && {
cmd="start"
}
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 18:10:31 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files
load_modules " "
configure_interfaces
verify_interfaces
reset_all
script_body
ip_forward
epilog_commands
RETVAL=$?
;;
stop)
stop_action
RETVAL=$?
;;
status)
status_action
RETVAL=$?
;;
block)
block_action
RETVAL=$?
;;
reload)
$0 stop
$0 start
RETVAL=$?
;;
interfaces)
configure_interfaces
RETVAL=$?
;;
test_interfaces)
FWBDEBUG="echo"
configure_interfaces
RETVAL=$?
;;
*)
echo "Usage $0 [start|stop|status|block|reload|interfaces|test_interfaces]"
;;
esac
exit $RETVAL

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:11 2011 PDT by vadim
# Generated Fri May 13 17:55:54 2011 PDT by vadim
#
# files: * firewall37.fw /etc/fw/firewall37.fw
#
@ -1284,7 +1284,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:11 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:54 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:10 2011 PDT by vadim
# Generated Fri May 13 17:55:56 2011 PDT by vadim
#
# files: * firewall38.fw /etc/fw/firewall38.fw
#
@ -519,7 +519,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:10 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:56 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:12 2011 PDT by vadim
# Generated Fri May 13 17:55:58 2011 PDT by vadim
#
# files: * firewall39.fw /etc/fw/firewall39.fw
#
@ -799,7 +799,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:12 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:55:58 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:13 2011 PDT by vadim
# Generated Fri May 13 17:56:00 2011 PDT by vadim
#
# files: * firewall4.fw /etc/fw/firewall4.fw
#
@ -710,7 +710,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:13 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:00 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:15 2011 PDT by vadim
# Generated Fri May 13 17:56:02 2011 PDT by vadim
#
# files: * firewall40-1.fw /etc/firewall40-1.fw
#
@ -441,7 +441,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:15 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:02 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:16 2011 PDT by vadim
# Generated Fri May 13 17:56:02 2011 PDT by vadim
#
# files: * firewall40-2.fw /etc/firewall40-2.fw
#
@ -428,7 +428,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:16 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:02 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:14 2011 PDT by vadim
# Generated Fri May 13 17:56:00 2011 PDT by vadim
#
# files: * firewall40.fw /etc/firewall40.fw
#
@ -434,7 +434,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:14 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:00 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:18 2011 PDT by vadim
# Generated Fri May 13 17:56:05 2011 PDT by vadim
#
# files: * firewall41-1.fw /etc/firewall41-1.fw
#
@ -575,7 +575,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:18 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:05 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:19 2011 PDT by vadim
# Generated Fri May 13 17:56:07 2011 PDT by vadim
#
# files: * firewall41.fw /etc/firewall41.fw
#
@ -459,7 +459,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:19 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:07 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:22 2011 PDT by vadim
# Generated Fri May 13 17:56:09 2011 PDT by vadim
#
# files: * firewall42.fw /etc/fw/firewall42.fw
#
@ -382,7 +382,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:22 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:09 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:22 2011 PDT by vadim
# Generated Fri May 13 17:56:09 2011 PDT by vadim
#
# files: * firewall5.fw /etc/fw/firewall5.fw
#
@ -622,7 +622,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:22 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:09 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:24 2011 PDT by vadim
# Generated Fri May 13 17:56:12 2011 PDT by vadim
#
# files: * firewall50.fw /etc/fw/firewall50.fw
#
@ -418,7 +418,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:24 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:12 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:24 2011 PDT by vadim
# Generated Fri May 13 17:56:12 2011 PDT by vadim
#
# files: * firewall51.fw /etc/fw/firewall51.fw
#
@ -491,7 +491,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:24 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:12 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:26 2011 PDT by vadim
# Generated Fri May 13 17:56:14 2011 PDT by vadim
#
# files: * firewall6.fw /etc/fw/firewall6.fw
#
@ -513,7 +513,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:26 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:14 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:26 2011 PDT by vadim
# Generated Fri May 13 17:56:14 2011 PDT by vadim
#
# files: * firewall60.fw /etc/firewall60.fw
#
@ -419,7 +419,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:26 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:14 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:28 2011 PDT by vadim
# Generated Fri May 13 17:56:17 2011 PDT by vadim
#
# files: * firewall61-1.2.5.fw /etc/firewall61-1.2.5.fw
#
@ -499,7 +499,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:28 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:17 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:28 2011 PDT by vadim
# Generated Fri May 13 17:56:17 2011 PDT by vadim
#
# files: * firewall61-1.2.6.fw /etc/firewall61-1.2.6.fw
#
@ -505,7 +505,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:28 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:17 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:30 2011 PDT by vadim
# Generated Fri May 13 17:56:19 2011 PDT by vadim
#
# files: * firewall61-1.3.x.fw /etc/firewall61-1.3.x.fw
#
@ -492,7 +492,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:30 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:19 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:31 2011 PDT by vadim
# Generated Fri May 13 17:56:19 2011 PDT by vadim
#
# files: * firewall61-1.4.fw /etc/firewall61-1.4.fw
#
@ -493,7 +493,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:31 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:19 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:33 2011 PDT by vadim
# Generated Fri May 13 17:56:21 2011 PDT by vadim
#
# files: * firewall62.fw /etc/firewall62.fw
#
@ -569,7 +569,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:33 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:21 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:33 2011 PDT by vadim
# Generated Fri May 13 17:56:21 2011 PDT by vadim
#
# files: * firewall63.fw /etc/firewall63.fw
#
@ -389,7 +389,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:33 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:21 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:35 2011 PDT by vadim
# Generated Fri May 13 17:56:24 2011 PDT by vadim
#
# files: * firewall7.fw /etc/fw/firewall7.fw
#
@ -473,7 +473,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:35 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:24 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:35 2011 PDT by vadim
# Generated Fri May 13 17:56:24 2011 PDT by vadim
#
# files: * firewall70.fw iptables.sh
#
@ -412,7 +412,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:35 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:24 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:37 2011 PDT by vadim
# Generated Fri May 13 17:56:26 2011 PDT by vadim
#
# files: * firewall71.fw /etc/fw/firewall71.fw
#
@ -428,7 +428,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:37 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:26 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:38 2011 PDT by vadim
# Generated Fri May 13 17:56:26 2011 PDT by vadim
#
# files: * firewall72-1.3.x.fw /etc/fw/firewall72-1.3.x.fw
#
@ -560,7 +560,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:38 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:26 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:40 2011 PDT by vadim
# Generated Fri May 13 17:56:29 2011 PDT by vadim
#
# files: * firewall72-1.4.3.fw /etc/fw/firewall72-1.4.3.fw
#
@ -560,7 +560,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:40 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:29 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:40 2011 PDT by vadim
# Generated Fri May 13 17:56:29 2011 PDT by vadim
#
# files: * firewall73.fw /etc/fw/firewall73.fw
#
@ -523,7 +523,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:40 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:29 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:42 2011 PDT by vadim
# Generated Fri May 13 17:56:31 2011 PDT by vadim
#
# files: * firewall74.fw /etc/fw/firewall74.fw
#
@ -375,7 +375,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:42 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:31 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:42 2011 PDT by vadim
# Generated Fri May 13 17:56:31 2011 PDT by vadim
#
# files: * firewall8.fw /etc/fw/firewall8.fw
#
@ -358,7 +358,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:42 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:31 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:44 2011 PDT by vadim
# Generated Fri May 13 17:56:33 2011 PDT by vadim
#
# files: * firewall80.fw /etc/fw/firewall80.fw
#
@ -399,7 +399,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:44 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:33 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:44 2011 PDT by vadim
# Generated Fri May 13 17:56:34 2011 PDT by vadim
#
# files: * firewall81.fw /etc/fw/firewall81.fw
#
@ -420,7 +420,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:44 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:34 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:46 2011 PDT by vadim
# Generated Fri May 13 17:56:36 2011 PDT by vadim
#
# files: * firewall82.fw /etc/firewall82.fw
#
@ -411,7 +411,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:46 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:36 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:46 2011 PDT by vadim
# Generated Fri May 13 17:56:36 2011 PDT by vadim
#
# files: * firewall82_A.fw /etc/fw/firewall82_A.fw
#
@ -400,7 +400,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:46 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:36 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:48 2011 PDT by vadim
# Generated Fri May 13 17:56:38 2011 PDT by vadim
#
# files: * firewall82_B.fw /etc/fw/firewall82_B.fw
#
@ -363,7 +363,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:48 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:38 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:49 2011 PDT by vadim
# Generated Fri May 13 17:56:38 2011 PDT by vadim
#
# files: * firewall9.fw /etc/fw/firewall9.fw
#
@ -621,7 +621,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:49 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:38 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:50 2011 PDT by vadim
# Generated Fri May 13 17:56:40 2011 PDT by vadim
#
# files: * firewall90.fw /etc/fw/firewall90.fw
#
@ -383,7 +383,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:50 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:40 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:51 2011 PDT by vadim
# Generated Fri May 13 17:56:41 2011 PDT by vadim
#
# files: * firewall91.fw /etc/fw/firewall91.fw
#
@ -383,7 +383,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:51 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:41 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:52 2011 PDT by vadim
# Generated Fri May 13 17:56:43 2011 PDT by vadim
#
# files: * firewall92.fw /etc/fw/firewall92.fw
#
@ -419,7 +419,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:52 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:43 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:53 2011 PDT by vadim
# Generated Fri May 13 17:56:43 2011 PDT by vadim
#
# files: * firewall93.fw /etc/fw/firewall93.fw
#
@ -458,7 +458,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:11:53 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:43 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:37 2011 PDT by vadim
# Generated Fri May 13 17:57:27 2011 PDT by vadim
#
# files: * fw-A.fw /sw/FWbuilder/fw-A.fw
#
@ -724,7 +724,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:37 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:27 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:36 2011 PDT by vadim
# Generated Fri May 13 17:57:25 2011 PDT by vadim
#
# files: * fw1.fw /etc/fw1.fw
#
@ -525,7 +525,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:36 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:25 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:11:20 2011 PDT by vadim
# Generated Fri May 13 17:56:07 2011 PDT by vadim
#
# files: * fwbuilder.fw /etc/init.d/fwbuilder.fw
#
@ -483,7 +483,7 @@ status_action() {
}
start() {
log "Activating firewall script generated Fri May 13 16:11:20 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:56:07 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:44 2011 PDT by vadim
# Generated Fri May 13 17:57:34 2011 PDT by vadim
#
# files: * heartbeat_cluster_1_d_linux-1-d.fw firewall.sh
#
@ -722,7 +722,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:44 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:34 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:44 2011 PDT by vadim
# Generated Fri May 13 17:57:34 2011 PDT by vadim
#
# files: * heartbeat_cluster_1_d_linux-2-d.fw firewall.sh
#
@ -726,7 +726,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:44 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:34 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:43 2011 PDT by vadim
# Generated Fri May 13 17:57:34 2011 PDT by vadim
#
# files: * heartbeat_cluster_1_linux-1.fw /etc/heartbeat_cluster_1_linux-1.fw
#
@ -843,7 +843,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:43 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:34 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:44 2011 PDT by vadim
# Generated Fri May 13 17:57:34 2011 PDT by vadim
#
# files: * heartbeat_cluster_1_linux-2.fw /etc/heartbeat_cluster_1_linux-2.fw
#
@ -741,7 +741,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:44 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:34 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:44 2011 PDT by vadim
# Generated Fri May 13 17:57:35 2011 PDT by vadim
#
# files: * heartbeat_cluster_2_linux-1.fw /etc/heartbeat_cluster_2_linux-1.fw
#
@ -707,7 +707,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:44 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:35 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:44 2011 PDT by vadim
# Generated Fri May 13 17:57:35 2011 PDT by vadim
#
# files: * heartbeat_cluster_2_linux-2.fw /etc/heartbeat_cluster_2_linux-2.fw
#
@ -620,7 +620,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:44 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:35 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:37 2011 PDT by vadim
# Generated Fri May 13 17:57:27 2011 PDT by vadim
#
# files: * host.fw /etc/fw/host.fw
#
@ -422,7 +422,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:37 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:27 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

File diff suppressed because it is too large Load Diff

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:44 2011 PDT by vadim
# Generated Fri May 13 17:57:35 2011 PDT by vadim
#
# files: * openais_cluster_1_linux-1.fw /etc/openais_cluster_1_linux-1.fw
#
@ -707,7 +707,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:44 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:35 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:44 2011 PDT by vadim
# Generated Fri May 13 17:57:35 2011 PDT by vadim
#
# files: * openais_cluster_1_linux-2.fw /etc/openais_cluster_1_linux-2.fw
#
@ -611,7 +611,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:44 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:35 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:39 2011 PDT by vadim
# Generated Fri May 13 18:21:21 2011 PDT by vadim
#
# files: * rc.firewall.local /etc/rc.d//rc.firewall.local
#

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:40 2011 PDT by vadim
# Generated Fri May 13 17:57:29 2011 PDT by vadim
#
# files: * rh90.fw /etc/rh90.fw
#
@ -421,7 +421,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:40 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:29 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:44 2011 PDT by vadim
# Generated Fri May 13 17:57:35 2011 PDT by vadim
#
# files: * secuwall_cluster_1_secuwall-1.fw /etc/secuwall_cluster_1_secuwall-1.fw
#
@ -405,7 +405,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:44 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:35 2011 by vadim"
log "Database was cluster-tests.fwb"
check_tools
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:45 2011 PDT by vadim
# Generated Fri May 13 17:57:35 2011 PDT by vadim
#
# files: * server-cluster-1_server-1.fw /etc/fw/server-cluster-1_server-1.fw
#
@ -400,7 +400,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:45 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:35 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:45 2011 PDT by vadim
# Generated Fri May 13 17:57:35 2011 PDT by vadim
#
# files: * server-cluster-1_server-2.fw /etc/fw/server-cluster-1_server-2.fw
#
@ -397,7 +397,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:45 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:35 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:41 2011 PDT by vadim
# Generated Fri May 13 17:57:31 2011 PDT by vadim
#
# files: * test-shadowing-1.fw /etc/test-shadowing-1.fw
#
@ -471,7 +471,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:41 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:31 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:43 2011 PDT by vadim
# Generated Fri May 13 17:57:33 2011 PDT by vadim
#
# files: * test-shadowing-2.fw /etc/test-shadowing-2.fw
#
@ -429,7 +429,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:43 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:33 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:43 2011 PDT by vadim
# Generated Fri May 13 17:57:34 2011 PDT by vadim
#
# files: * test-shadowing-3.fw /etc/test-shadowing-3.fw
#
@ -478,7 +478,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:43 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:34 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:41 2011 PDT by vadim
# Generated Fri May 13 17:57:31 2011 PDT by vadim
#
# files: * test_fw.fw /etc/test_fw.fw
#
@ -570,7 +570,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:41 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:31 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:45 2011 PDT by vadim
# Generated Fri May 13 17:57:35 2011 PDT by vadim
#
# files: * vrrp_cluster_1_linux-1.fw /etc/vrrp_cluster_1_linux-1.fw
#
@ -710,7 +710,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:45 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:35 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:45 2011 PDT by vadim
# Generated Fri May 13 17:57:36 2011 PDT by vadim
#
# files: * vrrp_cluster_1_linux-2.fw /etc/vrrp_cluster_1_linux-2.fw
#
@ -615,7 +615,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:45 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:36 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:45 2011 PDT by vadim
# Generated Fri May 13 17:57:36 2011 PDT by vadim
#
# files: * vrrp_cluster_2_linux-1.fw /etc/vrrp_cluster_2_linux-1.fw
#
@ -642,7 +642,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:45 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:36 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:45 2011 PDT by vadim
# Generated Fri May 13 17:57:36 2011 PDT by vadim
#
# files: * vrrp_cluster_2_linux-2.fw /etc/vrrp_cluster_2_linux-2.fw
#
@ -547,7 +547,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:45 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:36 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files

View File

@ -4,7 +4,7 @@
#
# Firewall Builder fwb_ipt v4.3.0.3542
#
# Generated Fri May 13 16:12:45 2011 PDT by vadim
# Generated Fri May 13 17:57:36 2011 PDT by vadim
#
# files: * vrrp_cluster_2_linux-3.fw /etc/vrrp_cluster_2_linux-3.fw
#
@ -523,7 +523,7 @@ test -z "$cmd" && {
case "$cmd" in
start)
log "Activating firewall script generated Fri May 13 16:12:45 2011 by vadim"
log "Activating firewall script generated Fri May 13 17:57:36 2011 by vadim"
check_tools
prolog_commands
check_run_time_address_table_files