fixes #2299 improvements in the log format of iptables and iosacl importers

This commit is contained in:
Vadim Kurland
2011-04-05 21:11:37 -07:00
parent 6f79c1d644
commit b1ad1cbec1
18 changed files with 443 additions and 402 deletions
+15
View File
@@ -249,6 +249,21 @@ void IOSImporter::ignoreCurrentInterface()
void IOSImporter::pushRule()
{
assert(current_ruleset!=NULL);
assert(current_rule!=NULL);
// populate all elements of the rule
addMessageToLog(
QString("access list rule: access list %1, action %2")
.arg(QString::fromUtf8(current_ruleset->ruleset->getName().c_str()))
.arg(action.c_str()));
Importer::pushRule();
}
void IOSImporter::MergeRules::move(FWObject* r)
{
PolicyRule *rule = PolicyRule::cast(r);
+2
View File
@@ -71,6 +71,8 @@ public:
virtual void ignoreCurrentInterface();
virtual void pushRule();
// this method actually adds interfaces to the firewall object
// and does final clean up.
virtual libfwbuilder::Firewall* finalize();
+59 -66
View File
@@ -401,9 +401,9 @@ void IPTImporter::processModuleMatches()
{
// at this time I create branches only one level deep
QString err = QObject::tr(
"Original rule combines match of tcp/udp/icmp \n"
"protocols with two or more module matches, such as \n"
"module 'mark', 'recent' or 'length'. Use additional \n"
"Original rule combines match of tcp/udp/icmp "
"protocols with two or more module matches, such as "
"module 'mark', 'recent' or 'length'. Use additional "
"branches to implement this complex match.");
reportError(err);
break;
@@ -586,8 +586,8 @@ PolicyRule* IPTImporter::createPolicyBranch(
ropt->setBool("stateless", true);
}
QString l("Created branch %1\n");
*Importer::logger << l.arg(branch_ruleset_name.c_str()).toUtf8().constData();
addMessageToLog(QString("Created branch %1")
.arg(QString::fromUtf8(branch_ruleset_name.c_str())));
return new_rule;
}
@@ -634,8 +634,9 @@ NATRule* IPTImporter::createNATBranch(
re = new_rule->getItfOutb(); re->reset();
}
QString l("Created branch %1\n");
*Importer::logger << l.arg(branch_ruleset_name.c_str()).toUtf8().constData();
addMessageToLog(
QString("Created branch %1")
.arg(QString::fromUtf8(branch_ruleset_name.c_str())));
return new_rule;
}
@@ -701,7 +702,7 @@ void IPTImporter::pushPolicyRule()
action_on_reject_code = "ICMP admin prohibited";
QString err = QObject::tr(
"Error: Line %1: Unknown parameter of target REJECT: %2.\n")
"Error: Line %1: Unknown parameter of target REJECT: %2.")
.arg(getCurrentLineNumber())
.arg(iptables_reject_arg);
reportError(err);
@@ -818,9 +819,9 @@ void IPTImporter::pushPolicyRule()
{
fwopt->setBool("clamp_mss_to_mtu", true);
skip_rule = true;
QString err("Warning: Line %1: Using automatic rule controlled by option "
"Clamp MSS to MTU\n");
*Importer::logger << err.arg(getCurrentLineNumber()).toStdString();
addMessageToLog(
QString("Warning: Using automatic rule controlled by option "
"Clamp MSS to MTU"));
}
if (target=="TOS")
@@ -914,15 +915,15 @@ void IPTImporter::pushPolicyRule()
srv->addRef(estab);
}
QString err(
"Warning: Line %1: Rule matches states 'RELATED,ESTABLISHED'. "
"Consider using "
"automatic rule controlled by the checkbox in the firewall "
"settings dialog. Automatic rule matches in all standard chains "
"which may be different from the original imported configuration. "
"This requires manual checking."
"\n");
*Importer::logger << err.arg(getCurrentLineNumber()).toStdString();
addMessageToLog(
QString(
"Warning: Rule matches states 'RELATED,ESTABLISHED'. "
"Consider using "
"automatic rule controlled by the checkbox in the firewall "
"settings dialog. Automatic rule matches in all standard chains "
"which may be different from the original imported configuration. "
"This requires manual checking."
));
current_state = "";
}
@@ -936,11 +937,11 @@ void IPTImporter::pushPolicyRule()
if (target=="LOG") fwopt->setBool("log_invalid", true);
skip_rule = true;
QString err("Warning: Line %1: Using automatic rule controlled by option "
"'Drop packet that do not match any known connection' to match "
"state INVALID"
"\n");
*Importer::logger << err.arg(getCurrentLineNumber()).toStdString();
addMessageToLog(
QString("Warning: Using automatic rule controlled by option "
"'Drop packet that do not match any known connection' "
"to match state INVALID"
));
current_state = "";
}
@@ -979,20 +980,18 @@ void IPTImporter::pushPolicyRule()
// --state NEW when service object adds its own state match
// ropt->setBool("stateless", false);
QString err(
"Warning: Line %1: Rule matches combination of states '%2'. "
"Iptables rules generated by fwbuilder can be stateless (match "
"no state) or stateful (match state NEW). Fwbuilder also adds "
"a rule at the top of the script to match states "
"ESTABLISHED,RELATED. Combination of states '%3' does not fit "
"these standard cases and to match it, the program created "
"new Custom Service object. This may require manual checking."
"\n");
*Importer::logger << err
.arg(getCurrentLineNumber())
addMessageToLog(
QString(
"Warning: Rule matches combination of states '%1'. "
"Iptables rules generated by fwbuilder can be stateless (match "
"no state) or stateful (match state NEW). Fwbuilder also adds "
"a rule at the top of the script to match states "
"ESTABLISHED,RELATED. Combination of states '%2' does not fit "
"these standard cases and to match it, the program created "
"new Custom Service object. This may require manual checking."
)
.arg(current_state.c_str())
.arg(current_state.c_str())
.toStdString();
.arg(current_state.c_str()));
current_state = "";
}
@@ -1007,11 +1006,11 @@ void IPTImporter::pushPolicyRule()
assert(lmr_ropt!=NULL);
lmr_ropt->setBool("ipt_mark_connections", true);
skip_rule = true;
QString err("Warning: Line %1: Turned option on in previous rule "
addMessageToLog(
QString("Warning: Turned option on in previous rule "
"with action Mark "
"for '-j CONNMARK --save-mark' "
"\n");
*Importer::logger << err.arg(getCurrentLineNumber()).toStdString();
));
}
if (target=="CONNMARK" &&
@@ -1021,10 +1020,10 @@ void IPTImporter::pushPolicyRule()
// MangleTableCompiler_ipt::flushAndSetDefaultPolicy()
// if we have at least one rule with CONNMARK target in the policy
skip_rule = true;
QString err("Warning: Line %1: Skip command with '-j CONNMARK --restore-mark' "
addMessageToLog(
QString("Warning: Skipping command with '-j CONNMARK --restore-mark' "
"This rule is generated automatically."
"\n");
*Importer::logger << err.arg(getCurrentLineNumber()).toStdString();
));
}
if (!skip_rule)
@@ -1117,12 +1116,10 @@ void IPTImporter::pushPolicyRule()
" Both inbound and outbound interfaces "
"in original iptables command: %1").arg(interfaces).toStdString();
QString log_str("Warning: Line %1: Creating branch ruleset '%2' to "
"match inbound and outbound interfaces %3\n");
*Importer::logger << log_str
.arg(getCurrentLineNumber())
.arg(branch_ruleset_name.c_str()).arg(interfaces)
.toUtf8().constData();
addMessageToLog(
QString("Warning: Creating branch ruleset '%1' to "
"match inbound and outbound interfaces %2")
.arg(branch_ruleset_name.c_str()).arg(interfaces));
} else
{
if ( !i_intf.empty())
@@ -1492,7 +1489,7 @@ Firewall* IPTImporter::finalize()
{
QString err = QObject::tr(
"Warning: Line %1: Can not reproduce default "
"action in table 'mangle' chain 'FORWARD'.\n"
"action in table 'mangle' chain 'FORWARD'. "
"(Generated rule may not generate equivalent "
"iptables command when compiled)"
);
@@ -1501,9 +1498,7 @@ Firewall* IPTImporter::finalize()
rule->setComment(
err.arg(
rs->default_action_line_number).toUtf8().constData());
*Importer::logger << err.arg(
rs->default_action_line_number).toUtf8().constData();
addMessageToLog(err.arg(rs->default_action_line_number));
}
}
@@ -1518,7 +1513,7 @@ Firewall* IPTImporter::finalize()
{
QString err = QObject::tr(
"Warning: Line %1: Can not reproduce default "
"action in table 'mangle' chain 'INPUT'.\n"
"action in table 'mangle' chain 'INPUT'. "
"(Generated rule may not generate equivalent "
"iptables command when compiled)"
);
@@ -1527,8 +1522,7 @@ Firewall* IPTImporter::finalize()
rule->setComment(
err.arg(
rs->default_action_line_number).toUtf8().constData());
*Importer::logger << err.arg(
rs->default_action_line_number).toUtf8().constData();
addMessageToLog(err.arg(rs->default_action_line_number));
}
}
@@ -1553,12 +1547,11 @@ Firewall* IPTImporter::finalize()
rs->ruleset->add(rule);
QString l("Warning: Line %1: Added rule to reproduce default "
"policy ACCEPT in %2\n");
*Importer::logger <<
l.arg(rs->default_action_line_number)
.arg(rs_index.c_str()).toUtf8().constData();
addMessageToLog(
QString("Warning: Line %1: Added rule to reproduce default "
"policy ACCEPT in %2")
.arg(rs->default_action_line_number)
.arg(rs_index.c_str()));
}
}
@@ -1682,9 +1675,9 @@ void IPTImporter::newUnidirRuleSet(const string &chain_name,
const string &ruleset_type)
{
current_ruleset = getUnidirRuleSet(chain_name, ruleset_type); // creates if new
QString l("Ruleset: %1 / %2\n");
*Importer::logger << l.arg(current_table.c_str()).arg(current_ruleset->name.c_str())
.toStdString();
addMessageToLog(
QString("New ruleset: %1 / %2")
.arg(current_table.c_str()).arg(current_ruleset->name.c_str()));
}
+1 -2
View File
@@ -803,8 +803,7 @@ void Importer::reportError(const std::string &comment)
void Importer::reportError(const QString &comment)
{
error_counter++;
QString err = QObject::tr("Parser error: Line %1: %2\n")
.arg(getCurrentLineNumber()).arg(comment);
QString err = QObject::tr("Error: %1").arg(comment);
addMessageToLog(err);
error_tracker->registerError(err);
}
+4 -1
View File
@@ -409,7 +409,10 @@ void PIXImporter::pushPolicyRule()
assert(current_rule!=NULL);
// populate all elements of the rule
addMessageToLog(QString("access list rule, action %1").arg(action.c_str()));
addMessageToLog(
QString("filtering rule: access list %1, action %2")
.arg(QString::fromUtf8(current_ruleset->ruleset->getName().c_str()))
.arg(action.c_str()));
PolicyRule *rule = PolicyRule::cast(current_rule);
@@ -1,47 +1,79 @@
Host name: "c3620"
New interface: FastEthernet0/0
Interface address: 192.168.100.100/255.255.255.0
Interface address: 10.3.14.201/255.255.255.0
Interface FastEthernet0/0 ruleset fe0_0_acl_in direction 'in'
Interface FastEthernet0/0 ruleset fe0_0_acl_out direction 'out'
New interface: Ethernet1/0
Interface comment: Test [ test ] { test } ( and one more test) / weird:characters#$%^&*/
Interface address: 192.168.171.2/255.255.255.0
Interface Ethernet1/0 ruleset e1_0_acl_in direction 'in'
Interface Ethernet1/0 ruleset e1_0_acl_out direction 'out'
New interface: Serial1/0
New interface: Ethernet1/1
Interface address: 10.10.10.10/255.255.255.0
Interface Ethernet1/1 ruleset acl_133 direction 'in'
Interface Ethernet1/1 ruleset acl_133 direction 'out'
New interface: Ethernet1/2
Interface address: 10.10.20.20/255.255.255.0
Interface Ethernet1/2 ruleset acl_133 direction 'in'
Interface Ethernet1/2 ruleset acl_133 direction 'out'
Ruleset: e1_0_acl_in
Ruleset: e1_0_acl_out
Ruleset: fe0_0_acl_in
Ruleset: fe0_0_acl_out
Ruleset: outside
Rule comment: / / path1/path2/path3
Rule comment: access list comment
Ruleset: tmp_acl
Ruleset: acl_133
Ruleset: acl_133
Ruleset: acl_133
Ruleset: acl_144
Ruleset: acl_144
Ruleset: acl_144
Ruleset: acl_144
Ruleset: acl_144
Ruleset: acl_144
Ruleset: acl_144
Ruleset: acl_144
Ruleset: acl_199
Ruleset: acl_199
Ruleset: acl_1300
Rule comment: Standard access lists are 1 to 99 and 1300 to 1999
Ruleset: acl_1300
Ruleset: acl_1300
Ruleset: acl_1300
Ruleset: acl_1300
10: Host name: "c3620"
104: New interface: FastEthernet0/0
105: Interface address: 192.168.100.100/255.255.255.0
106: Interface address: 10.3.14.201/255.255.255.0
107: Interface FastEthernet0/0 ruleset fe0_0_acl_in direction 'in'
108: Interface FastEthernet0/0 ruleset fe0_0_acl_out direction 'out'
113: New interface: Ethernet1/0
114: Interface comment: Test [ test ] { test } ( and one more test) / weird:characters#$%^&*/
115: Interface address: 192.168.171.2/255.255.255.0
116: Interface Ethernet1/0 ruleset e1_0_acl_in direction 'in'
117: Interface Ethernet1/0 ruleset e1_0_acl_out direction 'out'
123: New interface: Serial1/0
129: New interface: Ethernet1/1
130: Interface address: 10.10.10.10/255.255.255.0
134: Interface Ethernet1/1 ruleset acl_133 direction 'in'
135: Interface Ethernet1/1 ruleset acl_133 direction 'out'
139: New interface: Ethernet1/2
140: Interface address: 10.10.20.20/255.255.255.0
145: Interface Ethernet1/2 ruleset acl_133 direction 'in'
146: Interface Ethernet1/2 ruleset acl_133 direction 'out'
175: access list rule: access list e1_0_acl_in, action deny
176: access list rule: access list e1_0_acl_in, action permit
177: access list rule: access list e1_0_acl_in, action permit
178: access list rule: access list e1_0_acl_in, action permit
179: access list rule: access list e1_0_acl_in, action deny
182: access list rule: access list e1_0_acl_out, action permit
183: access list rule: access list e1_0_acl_out, action deny
186: access list rule: access list fe0_0_acl_in, action permit
187: access list rule: access list fe0_0_acl_in, action permit
188: access list rule: access list fe0_0_acl_in, action permit
189: access list rule: access list fe0_0_acl_in, action deny
192: access list rule: access list fe0_0_acl_out, action permit
193: access list rule: access list fe0_0_acl_out, action deny
196: Rule comment: / / path1/path2/path3
197: Rule comment: access list comment
199: access list rule: access list outside, action permit
201: access list rule: access list outside, action permit
203: access list rule: access list outside, action permit
205: access list rule: access list outside, action permit
206: access list rule: access list outside, action deny
208: access list rule: access list outside, action permit
210: access list rule: access list outside, action permit
211: access list rule: access list outside, action permit
214: access list rule: access list outside, action deny
215: access list rule: access list outside, action deny
216: access list rule: access list outside, action deny
217: access list rule: access list outside, action deny
219: access list rule: access list outside, action permit
220: access list rule: access list outside, action permit
222: access list rule: access list outside, action permit
224: access list rule: access list outside, action permit
226: access list rule: access list outside, action permit
227: access list rule: access list outside, action permit
228: access list rule: access list outside, action permit
232: access list rule: access list outside, action permit
233: access list rule: access list outside, action permit
234: access list rule: access list outside, action permit
236: access list rule: access list outside, action permit
237: access list rule: access list outside, action deny
240: access list rule: access list tmp_acl, action permit
241: access list rule: access list tmp_acl, action deny
243: access list rule: access list acl_133, action permit
244: access list rule: access list acl_133, action permit
245: access list rule: access list acl_133, action deny
246: access list rule: access list acl_144, action permit
247: access list rule: access list acl_144, action permit
248: access list rule: access list acl_144, action permit
249: access list rule: access list acl_144, action permit
250: access list rule: access list acl_144, action permit
251: access list rule: access list acl_144, action permit
252: access list rule: access list acl_144, action permit
253: access list rule: access list acl_144, action permit
254: access list rule: access list acl_199, action permit
255: access list rule: access list acl_199, action permit
257: Rule comment: Standard access lists are 1 to 99 and 1300 to 1999
258: access list rule: access list acl_1300, action permit
259: access list rule: access list acl_1300, action permit
260: access list rule: access list acl_1300, action permit
261: access list rule: access list acl_1300, action permit
@@ -1,6 +1,6 @@
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE FWObjectDatabase SYSTEM "fwbuilder.dtd">
<FWObjectDatabase xmlns="http://www.fwbuilder.org/1.0/" version="18" lastModified="1300949604" id="root">
<FWObjectDatabase xmlns="http://www.fwbuilder.org/1.0/" version="18" lastModified="1302063030" id="root">
<Library id="syslib000" color="#d4f8ff" name="Standard" comment="Standard objects" ro="True">
<AnyNetwork id="sysid0" name="Any" comment="Any Network" ro="False" address="0.0.0.0" netmask="0.0.0.0"/>
<AnyIPService id="sysid1" protocol_num="0" name="Any" comment="Any IP Service" ro="False"/>
@@ -3051,7 +3051,7 @@
<Option name="tagobject_id"></Option>
</PolicyRuleOptions>
</PolicyRule>
<PolicyRule id="id1612" disabled="False" group="" log="False" position="48" action="Branch" direction="Both" comment="Chain user_chain. &#10;Original rule combines match of tcp/udp/icmp &#10;protocols with two or more module matches, such as &#10;module 'mark', 'recent' or 'length'. Use additional &#10;branches to implement this complex match.&#10;Created during import of line 206">
<PolicyRule id="id1612" disabled="False" group="" log="False" position="48" action="Branch" direction="Both" comment="Chain user_chain. &#10;Created during import of line 206&#10;Error: Original rule combines match of tcp/udp/icmp protocols with two or more module matches, such as module 'mark', 'recent' or 'length'. Use additional branches to implement this complex match.">
<Src neg="False">
<ObjectRef ref="sysid0"/>
</Src>
@@ -3074,7 +3074,7 @@
<Option name="tagobject_id"></Option>
</PolicyRuleOptions>
</PolicyRule>
<PolicyRule id="id1624" disabled="False" group="" log="False" position="49" action="Branch" direction="Both" comment="Chain user_chain. &#10;Original rule combines match of tcp/udp/icmp &#10;protocols with two or more module matches, such as &#10;module 'mark', 'recent' or 'length'. Use additional &#10;branches to implement this complex match.&#10;Created during import of line 207">
<PolicyRule id="id1624" disabled="False" group="" log="False" position="49" action="Branch" direction="Both" comment="Chain user_chain. &#10;Created during import of line 207&#10;Error: Original rule combines match of tcp/udp/icmp protocols with two or more module matches, such as module 'mark', 'recent' or 'length'. Use additional branches to implement this complex match.">
<Src neg="False">
<ObjectRef ref="sysid0"/>
</Src>
@@ -3755,7 +3755,7 @@
<RuleSetOptions/>
</Policy>
<Policy id="id2003" name="Mangle" comment="" ro="False" ipv4_rule_set="False" ipv6_rule_set="False" top_rule_set="True">
<PolicyRule id="id2005" disabled="False" group="" log="False" position="0" action="Accept" direction="Both" comment="Warning: Line 220: Can not reproduce default action in table 'mangle' chain 'FORWARD'.&#10;(Generated rule may not generate equivalent iptables command when compiled)">
<PolicyRule id="id2005" disabled="False" group="" log="False" position="0" action="Accept" direction="Both" comment="Warning: Line 220: Can not reproduce default action in table 'mangle' chain 'FORWARD'. (Generated rule may not generate equivalent iptables command when compiled)">
<Src neg="False">
<ObjectRef ref="sysid0"/>
</Src>
@@ -3776,7 +3776,7 @@
<Option name="stateless">True</Option>
</PolicyRuleOptions>
</PolicyRule>
<PolicyRule id="id2017" disabled="False" group="" log="False" position="1" action="Accept" direction="Inbound" comment="Warning: Line 219: Can not reproduce default action in table 'mangle' chain 'INPUT'.&#10;(Generated rule may not generate equivalent iptables command when compiled)">
<PolicyRule id="id2017" disabled="False" group="" log="False" position="1" action="Accept" direction="Inbound" comment="Warning: Line 219: Can not reproduce default action in table 'mangle' chain 'INPUT'. (Generated rule may not generate equivalent iptables command when compiled)">
<Src neg="False">
<ObjectRef ref="sysid0"/>
</Src>
@@ -1,70 +1,66 @@
Ruleset: filter / INPUT
Default action: Deny
Ruleset: filter / FORWARD
Default action: Deny
Ruleset: filter / OUTPUT
Default action: Accept
Ruleset: filter / user_chain
Default action: Deny
Warning: Line 9: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
Warning: Line 12: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
Warning: Line 13: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
Warning: Line 14: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
Created branch INPUT_state_match_0
Warning: Line 18: Rule matches combination of states 'NEW,ESTABLISHED'. Iptables rules generated by fwbuilder can be stateless (match no state) or stateful (match state NEW). Fwbuilder also adds a rule at the top of the script to match states ESTABLISHED,RELATED. Combination of states 'NEW,ESTABLISHED' does not fit these standard cases and to match it, the program created new Custom Service object. This may require manual checking.
Created branch OUTPUT_established_1
Warning: Line 23: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
Created branch OUTPUT_established_2
Warning: Line 28: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
Warning: Line 31: Using automatic rule controlled by option 'Drop packet that do not match any known connection' to match state INVALID
Warning: Line 34: Using automatic rule controlled by option 'Drop packet that do not match any known connection' to match state INVALID
New interface: lo
Created branch Policy_eth1
New interface: eth1
New interface: eth0
Warning: Line 42: Creating branch ruleset 'Policy_eth1' to match inbound and outbound interfaces -i eth0 -o eth1
Warning: Line 103: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
Created branch user_chain_42_mod_match
Created branch user_chain_43_mod_match
Created branch user_chain_44_mod_match
Created branch user_chain_45_mod_match
Created branch user_chain_46_mod_match
Created branch user_chain_47_mod_match
Created branch user_chain_48_mod_match
Parser error: Line 206: Original rule combines match of tcp/udp/icmp
protocols with two or more module matches, such as
module 'mark', 'recent' or 'length'. Use additional
branches to implement this complex match.
Created branch user_chain_49_mod_match
Parser error: Line 207: Original rule combines match of tcp/udp/icmp
protocols with two or more module matches, such as
module 'mark', 'recent' or 'length'. Use additional
branches to implement this complex match.
Ruleset: mangle / PREROUTING
Default action: Accept
Ruleset: mangle / INPUT
Default action: Accept
Ruleset: mangle / FORWARD
Default action: Accept
Ruleset: mangle / OUTPUT
Default action: Accept
Ruleset: mangle / POSTROUTING
Default action: Accept
Warning: Line 235: Skip command with '-j CONNMARK --restore-mark' This rule is generated automatically.
Warning: Line 239: Turned option on in previous rule with action Mark for '-j CONNMARK --save-mark'
New interface: eth2
Ruleset: nat / PREROUTING
Default action: Accept
Ruleset: nat / POSTROUTING
Default action: Accept
Ruleset: nat / OUTPUT
Default action: Accept
New interface: eth+
Warning: Line 5: Added rule to reproduce default policy ACCEPT in filter/OUTPUT
Warning: Line 220: Can not reproduce default action in table 'mangle' chain 'FORWARD'.
(Generated rule may not generate equivalent iptables command when compiled)Warning: Line 220: Added rule to reproduce default policy ACCEPT in mangle/FORWARD
Warning: Line 219: Can not reproduce default action in table 'mangle' chain 'INPUT'.
(Generated rule may not generate equivalent iptables command when compiled)Warning: Line 219: Added rule to reproduce default policy ACCEPT in mangle/INPUT
Warning: Line 221: Added rule to reproduce default policy ACCEPT in mangle/OUTPUT
Warning: Line 222: Added rule to reproduce default policy ACCEPT in mangle/POSTROUTING
Warning: Line 218: Added rule to reproduce default policy ACCEPT in mangle/PREROUTING
3: New ruleset: filter / INPUT
3: Default action: Deny
4: New ruleset: filter / FORWARD
4: Default action: Deny
5: New ruleset: filter / OUTPUT
5: Default action: Accept
6: New ruleset: filter / user_chain
6: Default action: Deny
9: Warning: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
12: Warning: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
13: Warning: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
14: Warning: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
18: Created branch INPUT_state_match_0
18: Warning: Rule matches combination of states 'NEW,ESTABLISHED'. Iptables rules generated by fwbuilder can be stateless (match no state) or stateful (match state NEW). Fwbuilder also adds a rule at the top of the script to match states ESTABLISHED,RELATED. Combination of states 'NEW,ESTABLISHED' does not fit these standard cases and to match it, the program created new Custom Service object. This may require manual checking.
23: Created branch OUTPUT_established_1
23: Warning: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
28: Created branch OUTPUT_established_2
28: Warning: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
31: Warning: Using automatic rule controlled by option 'Drop packet that do not match any known connection' to match state INVALID
34: Warning: Using automatic rule controlled by option 'Drop packet that do not match any known connection' to match state INVALID
37: New interface: lo
42: Created branch Policy_eth1
42: New interface: eth1
42: New interface: eth0
42: Warning: Creating branch ruleset 'Policy_eth1' to match inbound and outbound interfaces -i eth0 -o eth1
103: Warning: Rule matches states 'RELATED,ESTABLISHED'. Consider using automatic rule controlled by the checkbox in the firewall settings dialog. Automatic rule matches in all standard chains which may be different from the original imported configuration. This requires manual checking.
191: Created branch user_chain_42_mod_match
195: Created branch user_chain_43_mod_match
196: Created branch user_chain_44_mod_match
197: Created branch user_chain_45_mod_match
200: Created branch user_chain_46_mod_match
203: Created branch user_chain_47_mod_match
206: Created branch user_chain_48_mod_match
206: Error: Original rule combines match of tcp/udp/icmp protocols with two or more module matches, such as module 'mark', 'recent' or 'length'. Use additional branches to implement this complex match.
206: Error: Error: Original rule combines match of tcp/udp/icmp protocols with two or more module matches, such as module 'mark', 'recent' or 'length'. Use additional branches to implement this complex match.
207: Created branch user_chain_49_mod_match
207: Error: Original rule combines match of tcp/udp/icmp protocols with two or more module matches, such as module 'mark', 'recent' or 'length'. Use additional branches to implement this complex match.
207: Error: Error: Original rule combines match of tcp/udp/icmp protocols with two or more module matches, such as module 'mark', 'recent' or 'length'. Use additional branches to implement this complex match.
218: New ruleset: mangle / PREROUTING
218: Default action: Accept
219: New ruleset: mangle / INPUT
219: Default action: Accept
220: New ruleset: mangle / FORWARD
220: Default action: Accept
221: New ruleset: mangle / OUTPUT
221: Default action: Accept
222: New ruleset: mangle / POSTROUTING
222: Default action: Accept
235: Warning: Skipping command with '-j CONNMARK --restore-mark' This rule is generated automatically.
239: Warning: Turned option on in previous rule with action Mark for '-j CONNMARK --save-mark'
243: New interface: eth2
253: New ruleset: nat / PREROUTING
253: Default action: Accept
254: New ruleset: nat / POSTROUTING
254: Default action: Accept
255: New ruleset: nat / OUTPUT
255: Default action: Accept
259: New interface: eth+
286: Warning: Line 5: Added rule to reproduce default policy ACCEPT in filter/OUTPUT
286: Warning: Line 220: Can not reproduce default action in table 'mangle' chain 'FORWARD'. (Generated rule may not generate equivalent iptables command when compiled)
286: Warning: Line 220: Added rule to reproduce default policy ACCEPT in mangle/FORWARD
286: Warning: Line 219: Can not reproduce default action in table 'mangle' chain 'INPUT'. (Generated rule may not generate equivalent iptables command when compiled)
286: Warning: Line 219: Added rule to reproduce default policy ACCEPT in mangle/INPUT
286: Warning: Line 221: Added rule to reproduce default policy ACCEPT in mangle/OUTPUT
286: Warning: Line 222: Added rule to reproduce default policy ACCEPT in mangle/POSTROUTING
286: Warning: Line 218: Added rule to reproduce default policy ACCEPT in mangle/PREROUTING
@@ -5,3 +5,4 @@ HEADERS += PIXImporterTest.h
SOURCES += main_PIXImporterTest.cpp \
PIXImporterTest.cpp
STATIC_LIBS += ../../libgui/libgui.a
@@ -37,36 +37,36 @@ Warning: interface Ethernet4 was not imported because it is in "shutdown" mode
99: Object Group (protocol) proto-tcp
101: Object Group (protocol) proto-udp
108: Interface Ethernet1 ruleset icmp_commands_outside direction 'in'
108: access list rule, action permit
108: filtering rule: access list icmp_commands_outside, action permit
109: Interface Ethernet1 ruleset icmp_commands_outside direction 'in'
109: access list rule, action permit
109: filtering rule: access list icmp_commands_outside, action permit
110: Interface Ethernet1 ruleset icmp_commands_outside direction 'in'
110: access list rule, action permit
110: filtering rule: access list icmp_commands_outside, action permit
111: Interface Ethernet1 ruleset icmp_commands_outside direction 'in'
111: access list rule, action permit
111: filtering rule: access list icmp_commands_outside, action permit
112: Interface Ethernet1 ruleset icmp_commands_outside direction 'in'
112: access list rule, action permit
112: filtering rule: access list icmp_commands_outside, action permit
113: Interface Ethernet1 ruleset icmp_commands_outside direction 'in'
113: access list rule, action permit
113: filtering rule: access list icmp_commands_outside, action permit
114: Interface Ethernet0 ruleset icmp_commands_inside direction 'in'
114: access list rule, action permit
114: filtering rule: access list icmp_commands_inside, action permit
115: Interface Ethernet0 ruleset icmp_commands_inside direction 'in'
115: access list rule, action permit
115: filtering rule: access list icmp_commands_inside, action permit
116: Interface Ethernet0 ruleset icmp_commands_inside direction 'in'
116: access list rule, action permit
116: filtering rule: access list icmp_commands_inside, action permit
117: Interface Ethernet0 ruleset icmp_commands_inside direction 'in'
117: access list rule, action permit
117: filtering rule: access list icmp_commands_inside, action permit
118: Interface Ethernet0 ruleset icmp_commands_inside direction 'in'
118: access list rule, action permit
118: filtering rule: access list icmp_commands_inside, action permit
119: Interface Ethernet0 ruleset icmp_commands_inside direction 'in'
119: access list rule, action permit
119: filtering rule: access list icmp_commands_inside, action permit
120: Interface Ethernet0 ruleset icmp_commands_inside direction 'in'
120: access list rule, action permit
120: filtering rule: access list icmp_commands_inside, action permit
121: Interface Ethernet0 ruleset icmp_commands_inside direction 'in'
121: access list rule, action permit
121: filtering rule: access list icmp_commands_inside, action permit
122: Interface Ethernet0 ruleset icmp_commands_inside direction 'in'
122: access list rule, action permit
122: filtering rule: access list icmp_commands_inside, action permit
135: Interface Ethernet0 ruleset telnet_commands_inside direction 'in'
135: access list rule, action permit
135: filtering rule: access list telnet_commands_inside, action permit
137: Interface Ethernet0 ruleset ssh_commands_inside direction 'in'
137: access list rule, action permit
137: filtering rule: access list ssh_commands_inside, action permit
@@ -20,36 +20,36 @@
104: Object Group (protocol) pg1
110: Object Group (network) src-network-group-1
114: Object Group (network) dst-network-group-1
122: access list rule, action permit
125: access list rule, action permit
127: access list rule, action permit
129: access list rule, action permit
131: access list rule, action permit
133: access list rule, action permit
138: access list rule, action permit
143: access list rule, action permit
145: access list rule, action permit
147: access list rule, action permit
149: access list rule, action permit
155: access list rule, action permit
122: filtering rule: access list inside_in, action permit
125: filtering rule: access list inside_in, action permit
127: filtering rule: access list inside_in, action permit
129: filtering rule: access list inside_in, action permit
131: filtering rule: access list inside_in, action permit
133: filtering rule: access list inside_in, action permit
138: filtering rule: access list inside_in, action permit
143: filtering rule: access list inside_in, action permit
145: filtering rule: access list inside_in, action permit
147: filtering rule: access list inside_in, action permit
149: filtering rule: access list inside_in, action permit
155: filtering rule: access list inside_in, action permit
155: Object Group (service) srv-group-1-mirror
162: access list rule, action permit
164: access list rule, action permit
166: access list rule, action permit
168: access list rule, action permit
170: access list rule, action permit
175: access list rule, action permit
177: access list rule, action permit
179: access list rule, action permit
181: access list rule, action permit
188: access list rule, action permit
162: filtering rule: access list inside_in, action permit
164: filtering rule: access list inside_in, action permit
166: filtering rule: access list inside_in, action permit
168: filtering rule: access list inside_in, action permit
170: filtering rule: access list inside_in, action permit
175: filtering rule: access list inside_in, action permit
177: filtering rule: access list inside_in, action permit
179: filtering rule: access list inside_in, action permit
181: filtering rule: access list inside_in, action permit
188: filtering rule: access list inside_in, action permit
188: Object Group (service) srv-group-1-mirror
190: access list rule, action permit
190: filtering rule: access list inside_in, action permit
190: Object Group (service) srv-group-1-mirror
192: access list rule, action permit
192: filtering rule: access list inside_in, action permit
192: Object Group (service) srv-group-1-mirror
194: access list rule, action permit
194: filtering rule: access list inside_in, action permit
194: Object Group (service) srv-group-1-mirror
196: access list rule, action permit
196: filtering rule: access list inside_in, action permit
196: Object Group (service) srv-group-1-mirror
199: Interface Vlan1 ruleset inside_in direction 'in'
@@ -27,86 +27,86 @@
129: Object Group (service) test-service-3
133: Object Group (service) test-service-4
144: Rule comment: 0 ( global )
148: access list rule, action permit
149: access list rule, action permit
150: access list rule, action permit
151: access list rule, action permit
152: access list rule, action permit
154: access list rule, action permit
155: access list rule, action permit
156: access list rule, action permit
157: access list rule, action permit
158: access list rule, action permit
159: access list rule, action permit
160: access list rule, action permit
161: access list rule, action permit
162: access list rule, action permit
163: access list rule, action permit
164: access list rule, action permit
165: access list rule, action permit
166: access list rule, action permit
167: access list rule, action permit
168: access list rule, action permit
171: access list rule, action permit
148: filtering rule: access list inside_in, action permit
149: filtering rule: access list inside_in, action permit
150: filtering rule: access list inside_in, action permit
151: filtering rule: access list inside_in, action permit
152: filtering rule: access list inside_in, action permit
154: filtering rule: access list inside_in, action permit
155: filtering rule: access list inside_in, action permit
156: filtering rule: access list inside_in, action permit
157: filtering rule: access list inside_in, action permit
158: filtering rule: access list inside_in, action permit
159: filtering rule: access list inside_in, action permit
160: filtering rule: access list inside_in, action permit
161: filtering rule: access list inside_in, action permit
162: filtering rule: access list inside_in, action permit
163: filtering rule: access list inside_in, action permit
164: filtering rule: access list inside_in, action permit
165: filtering rule: access list inside_in, action permit
166: filtering rule: access list inside_in, action permit
167: filtering rule: access list inside_in, action permit
168: filtering rule: access list inside_in, action permit
171: filtering rule: access list inside_in, action permit
172: Rule comment: 3 ( global )
175: access list rule, action deny
177: access list rule, action deny
179: access list rule, action deny
180: access list rule, action deny
181: access list rule, action deny
183: access list rule, action deny
189: access list rule, action permit
175: filtering rule: access list inside_in, action deny
177: filtering rule: access list inside_in, action deny
179: filtering rule: access list inside_in, action deny
180: filtering rule: access list inside_in, action deny
181: filtering rule: access list inside_in, action deny
183: filtering rule: access list inside_in, action deny
189: filtering rule: access list inside_in, action permit
189: Object Group (service) id5102X14531.srv.tcp.0-mirror
191: access list rule, action permit
193: access list rule, action permit
194: access list rule, action permit
195: access list rule, action permit
196: access list rule, action permit
197: access list rule, action permit
199: access list rule, action permit
191: filtering rule: access list inside_in, action permit
193: filtering rule: access list inside_in, action permit
194: filtering rule: access list inside_in, action permit
195: filtering rule: access list inside_in, action permit
196: filtering rule: access list inside_in, action permit
197: filtering rule: access list inside_in, action permit
199: filtering rule: access list inside_in, action permit
199: Object Group (service) id5102X14531.srv.tcp.0-mirror
200: access list rule, action permit
201: access list rule, action permit
202: access list rule, action permit
203: access list rule, action permit
204: access list rule, action permit
206: access list rule, action permit
207: access list rule, action permit
208: access list rule, action permit
209: access list rule, action permit
210: access list rule, action permit
211: access list rule, action permit
213: access list rule, action permit
214: access list rule, action permit
215: access list rule, action permit
216: access list rule, action permit
217: access list rule, action permit
218: access list rule, action permit
221: access list rule, action permit
200: filtering rule: access list inside_in, action permit
201: filtering rule: access list inside_in, action permit
202: filtering rule: access list inside_in, action permit
203: filtering rule: access list inside_in, action permit
204: filtering rule: access list inside_in, action permit
206: filtering rule: access list inside_out, action permit
207: filtering rule: access list inside_out, action permit
208: filtering rule: access list inside_out, action permit
209: filtering rule: access list inside_out, action permit
210: filtering rule: access list inside_out, action permit
211: filtering rule: access list inside_out, action permit
213: filtering rule: access list inside_out, action permit
214: filtering rule: access list inside_out, action permit
215: filtering rule: access list inside_out, action permit
216: filtering rule: access list inside_out, action permit
217: filtering rule: access list inside_out, action permit
218: filtering rule: access list inside_out, action permit
221: filtering rule: access list inside_out, action permit
221: Error: tcp port name 'foo' is unknown
223: access list rule, action permit
225: access list rule, action permit
227: access list rule, action permit
229: access list rule, action permit
231: access list rule, action permit
232: access list rule, action permit
234: access list rule, action permit
235: access list rule, action permit
236: access list rule, action permit
240: access list rule, action permit
223: filtering rule: access list inside_out, action permit
225: filtering rule: access list inside_out, action permit
227: filtering rule: access list inside_out, action permit
229: filtering rule: access list inside_out, action permit
231: filtering rule: access list inside_out, action permit
232: filtering rule: access list inside_out, action permit
234: filtering rule: access list outside_out, action permit
235: filtering rule: access list outside_out, action permit
236: filtering rule: access list outside_out, action permit
240: filtering rule: access list outside_in, action permit
240: Object Group (service) test-service-1-mirror
241: access list rule, action permit
241: filtering rule: access list outside_in, action permit
241: Object Group (service) test-service-2-mirror
242: access list rule, action permit
242: filtering rule: access list outside_in, action permit
242: Object Group (service) test-service-3-mirror
242: Object Group (service) test-service-1-mirror
243: access list rule, action permit
243: filtering rule: access list outside_in, action permit
243: Object Group (service) test-service-4-mirror
243: Object Group (service) test-service-1-mirror
247: access list rule, action permit
248: access list rule, action permit
249: access list rule, action permit
250: access list rule, action permit
247: filtering rule: access list outside_in, action permit
248: filtering rule: access list outside_in, action permit
249: filtering rule: access list outside_in, action permit
250: filtering rule: access list outside_in, action permit
268: Interface Vlan1 ruleset inside_in direction 'in'
269: Interface Vlan1 ruleset inside_out direction 'out'
270: Interface Vlan2 ruleset outside_in direction 'in'
@@ -107,5 +107,5 @@
290: Object Group (icmp) ig3
296: Object Group (service) id5102X14531.srv.tcp.0
301: Object Group (service) tcp-udp-1
304: access list rule, action permit
304: filtering rule: access list inside_in, action permit
305: Interface Vlan1 ruleset inside_in direction 'in'
@@ -37,14 +37,14 @@ Warning: interface Ethernet0/7 was not imported because it is in "shutdown" mode
56: Named object (address) internal_subnet_2
59: Named object (address) Internal_net
61: Named object (address) hostA:eth0
65: access list rule, action deny
65: filtering rule: access list outside_acl_in, action deny
84: Interface Vlan1 ruleset http_commands_inside direction 'in'
84: access list rule, action permit
84: filtering rule: access list http_commands_inside, action permit
85: Interface Vlan1 ruleset http_commands_inside direction 'in'
85: access list rule, action permit
85: filtering rule: access list http_commands_inside, action permit
86: Interface Vlan1 ruleset http_commands_inside direction 'in'
86: access list rule, action permit
86: filtering rule: access list http_commands_inside, action permit
95: Interface Vlan1 ruleset ssh_commands_inside direction 'in'
95: access list rule, action permit
95: filtering rule: access list ssh_commands_inside, action permit
96: Interface Vlan1 ruleset ssh_commands_inside direction 'in'
96: access list rule, action permit
96: filtering rule: access list ssh_commands_inside, action permit
@@ -11,97 +11,97 @@
46: Object Group (service) outside.id12438X2458.srv.tcp.0
49: Object Group (service) outside.id12466X2458.srv.tcp.0
52: Rule comment: 0 ( ethernet0 )
53: access list rule, action deny
54: access list rule, action deny
53: filtering rule: access list outside_acl_in, action deny
54: filtering rule: access list outside_acl_in, action deny
55: Rule comment: 3 ( global )
56: access list rule, action permit
56: filtering rule: access list outside_acl_in, action permit
58: Rule comment: 4 ( global )
59: Rule comment: fw uses DHCP
60: Rule comment: plus many DHCP requests
61: Rule comment: from cable modem
64: Rule comment: 6 ( global )
65: access list rule, action deny
65: filtering rule: access list outside_acl_in, action deny
66: Rule comment: 7 ( global )
67: access list rule, action permit
67: filtering rule: access list outside_acl_in, action permit
68: Rule comment: 10 ( global )
69: Rule comment: using swatch to automatically
70: Rule comment: block probing ssh connections , so no
71: Rule comment: need to limit
72: access list rule, action permit
73: access list rule, action permit
72: filtering rule: access list outside_acl_in, action permit
73: filtering rule: access list outside_acl_in, action permit
75: Rule comment: 11 ( global )
76: access list rule, action permit
77: access list rule, action permit
76: filtering rule: access list outside_acl_in, action permit
77: filtering rule: access list outside_acl_in, action permit
79: Rule comment: 17 ( global )
80: access list rule, action permit
81: access list rule, action permit
80: filtering rule: access list outside_acl_in, action permit
81: filtering rule: access list outside_acl_in, action permit
82: Rule comment: 19 ( global )
83: Rule comment: ' catch all' rule
84: access list rule, action deny
84: filtering rule: access list outside_acl_in, action deny
85: Rule comment: 1 ( global )
86: access list rule, action permit
87: access list rule, action permit
86: filtering rule: access list inside_acl_in, action permit
87: filtering rule: access list inside_acl_in, action permit
93: Rule comment: 5 ( global )
94: access list rule, action permit
94: filtering rule: access list inside_acl_in, action permit
95: Rule comment: 6 ( global )
96: access list rule, action deny
96: filtering rule: access list inside_acl_in, action deny
97: Rule comment: 7 ( global )
98: access list rule, action permit
98: filtering rule: access list inside_acl_in, action permit
106: Rule comment: 17 ( global )
107: access list rule, action permit
108: access list rule, action permit
107: filtering rule: access list inside_acl_in, action permit
108: filtering rule: access list inside_acl_in, action permit
109: Rule comment: 18 ( global )
110: access list rule, action permit
110: filtering rule: access list inside_acl_in, action permit
111: Rule comment: 19 ( global )
112: Rule comment: ' catch all' rule
113: access list rule, action deny
114: access list rule, action permit
115: access list rule, action permit
116: access list rule, action permit
117: access list rule, action permit
118: access list rule, action permit
119: access list rule, action permit
120: access list rule, action permit
121: access list rule, action permit
122: access list rule, action permit
123: access list rule, action permit
124: access list rule, action permit
125: access list rule, action permit
113: filtering rule: access list inside_acl_in, action deny
114: filtering rule: access list id12594X2458.0, action permit
115: filtering rule: access list id12594X2458.1, action permit
116: filtering rule: access list id12594X2458.2, action permit
117: filtering rule: access list id12594X2458.3, action permit
118: filtering rule: access list id12626X2458.0, action permit
119: filtering rule: access list id12626X2458.1, action permit
120: filtering rule: access list id12626X2458.2, action permit
121: filtering rule: access list id12642X2458.0, action permit
122: filtering rule: access list id12656X2458.0, action permit
123: filtering rule: access list id12670X2458.0, action permit
124: filtering rule: access list id12684X2458.0, action permit
125: filtering rule: access list id12743X2458.0, action permit
127: Interface ethernet0 ruleset outside_acl_in direction 'in'
128: Interface ethernet1 ruleset inside_acl_in direction 'in'
140: Interface ethernet0 ruleset icmp_commands_outside direction 'in'
140: access list rule, action permit
140: filtering rule: access list icmp_commands_outside, action permit
141: Interface ethernet0 ruleset icmp_commands_outside direction 'in'
141: access list rule, action permit
141: filtering rule: access list icmp_commands_outside, action permit
142: Interface ethernet0 ruleset icmp_commands_outside direction 'in'
142: access list rule, action permit
142: filtering rule: access list icmp_commands_outside, action permit
143: Interface ethernet0 ruleset icmp_commands_outside direction 'in'
143: access list rule, action permit
143: filtering rule: access list icmp_commands_outside, action permit
144: Interface ethernet0 ruleset icmp_commands_outside direction 'in'
144: access list rule, action permit
144: filtering rule: access list icmp_commands_outside, action permit
145: Interface ethernet0 ruleset icmp_commands_outside direction 'in'
145: access list rule, action permit
145: filtering rule: access list icmp_commands_outside, action permit
146: Interface ethernet1 ruleset icmp_commands_inside direction 'in'
146: access list rule, action permit
146: filtering rule: access list icmp_commands_inside, action permit
147: Interface ethernet1 ruleset icmp_commands_inside direction 'in'
147: access list rule, action permit
147: filtering rule: access list icmp_commands_inside, action permit
148: Interface ethernet1 ruleset icmp_commands_inside direction 'in'
148: access list rule, action permit
148: filtering rule: access list icmp_commands_inside, action permit
149: Interface ethernet1 ruleset icmp_commands_inside direction 'in'
149: access list rule, action permit
149: filtering rule: access list icmp_commands_inside, action permit
150: Interface ethernet1 ruleset icmp_commands_inside direction 'in'
150: access list rule, action permit
150: filtering rule: access list icmp_commands_inside, action permit
151: Interface ethernet1 ruleset icmp_commands_inside direction 'in'
151: access list rule, action permit
151: filtering rule: access list icmp_commands_inside, action permit
152: Interface ethernet1 ruleset icmp_commands_inside direction 'in'
152: access list rule, action permit
152: filtering rule: access list icmp_commands_inside, action permit
153: Interface ethernet1 ruleset icmp_commands_inside direction 'in'
153: access list rule, action permit
153: filtering rule: access list icmp_commands_inside, action permit
154: Interface ethernet1 ruleset icmp_commands_inside direction 'in'
154: access list rule, action permit
154: filtering rule: access list icmp_commands_inside, action permit
156: Interface ethernet1 ruleset telnet_commands_inside direction 'in'
156: access list rule, action permit
156: filtering rule: access list telnet_commands_inside, action permit
158: Interface ethernet1 ruleset ssh_commands_inside direction 'in'
158: access list rule, action permit
158: filtering rule: access list ssh_commands_inside, action permit
159: Interface ethernet1 ruleset ssh_commands_inside direction 'in'
159: access list rule, action permit
159: filtering rule: access list ssh_commands_inside, action permit
@@ -33,24 +33,24 @@ Warning: interface Ethernet6 was not imported because it is in "shutdown" mode
79: Object Group (network) outside.id12051X6282.src.net.2
83: Object Group (network) network-zone-inside
85: Object Group (network) network-zone-dmz20
89: access list rule, action deny
90: access list rule, action deny
91: access list rule, action deny
92: access list rule, action deny
93: access list rule, action permit
94: access list rule, action permit
95: access list rule, action permit
96: access list rule, action permit
97: access list rule, action deny
98: access list rule, action deny
99: access list rule, action deny
100: access list rule, action deny
101: access list rule, action permit
102: access list rule, action deny
104: access list rule, action permit
106: access list rule, action permit
109: access list rule, action permit
111: access list rule, action permit
89: filtering rule: access list outside_in, action deny
90: filtering rule: access list outside_in, action deny
91: filtering rule: access list outside_in, action deny
92: filtering rule: access list outside_in, action deny
93: filtering rule: access list inside_out, action permit
94: filtering rule: access list inside_out, action permit
95: filtering rule: access list inside_out, action permit
96: filtering rule: access list inside_out, action permit
97: filtering rule: access list inside_out, action deny
98: filtering rule: access list inside_in, action deny
99: filtering rule: access list inside_in, action deny
100: filtering rule: access list inside_in, action deny
101: filtering rule: access list inside_in, action permit
102: filtering rule: access list inside_in, action deny
104: filtering rule: access list id12251X6282.0, action permit
106: filtering rule: access list id12594X2458.0, action permit
109: filtering rule: access list WEB, action permit
111: filtering rule: access list NET1, action permit
138: Global address pool: number 1, interface outside, address range interface-interface, netmask 255.255.255.255
139: Source translation rule ("nat" command)
141: Global address pool: number 2, interface outside, address range 192.0.2.10-192.0.2.10, netmask 255.255.255.255
@@ -73,8 +73,8 @@ Warning: interface Ethernet6 was not imported because it is in "shutdown" mode
165: Interface Ethernet1 ruleset inside_in direction 'in'
166: Interface Ethernet1 ruleset inside_out direction 'out'
207: Interface Ethernet1 ruleset ssh_commands_inside direction 'in'
207: access list rule, action permit
207: filtering rule: access list ssh_commands_inside, action permit
208: Interface Ethernet1 ruleset ssh_commands_inside direction 'in'
208: access list rule, action permit
208: filtering rule: access list ssh_commands_inside, action permit
209: Interface Ethernet0.101 ruleset ssh_commands_outside direction 'in'
209: access list rule, action permit
209: filtering rule: access list ssh_commands_outside, action permit
@@ -31,29 +31,29 @@ Warning: interface Ethernet6 was not imported because it is in "shutdown" mode
70: Object Group (network) outside.id12051X6282.src.net.0
73: Object Group (network) outside.id12051X6282.src.net.1
78: Object Group (network) outside.id12051X6282.src.net.2
81: access list rule, action deny
82: access list rule, action deny
83: access list rule, action deny
84: access list rule, action deny
85: access list rule, action permit
86: access list rule, action permit
87: access list rule, action permit
88: access list rule, action permit
89: access list rule, action deny
90: access list rule, action deny
91: access list rule, action deny
92: access list rule, action deny
93: access list rule, action permit
94: access list rule, action deny
95: access list rule, action permit
81: filtering rule: access list outside_in, action deny
82: filtering rule: access list outside_in, action deny
83: filtering rule: access list outside_in, action deny
84: filtering rule: access list outside_in, action deny
85: filtering rule: access list inside_out, action permit
86: filtering rule: access list inside_out, action permit
87: filtering rule: access list inside_out, action permit
88: filtering rule: access list inside_out, action permit
89: filtering rule: access list inside_out, action deny
90: filtering rule: access list inside_in, action deny
91: filtering rule: access list inside_in, action deny
92: filtering rule: access list inside_in, action deny
93: filtering rule: access list inside_in, action permit
94: filtering rule: access list inside_in, action deny
95: filtering rule: access list id12251X6282.0, action permit
97: Interface Ethernet1 ruleset inside_in direction 'in'
98: Interface Ethernet0.101 ruleset outside_in direction 'in'
123: Interface Ethernet0.101 ruleset outside_in direction 'in'
124: Interface Ethernet1 ruleset inside_in direction 'in'
125: Interface Ethernet1 ruleset inside_out direction 'out'
164: Interface Ethernet1 ruleset ssh_commands_inside direction 'in'
164: access list rule, action permit
164: filtering rule: access list ssh_commands_inside, action permit
165: Interface Ethernet1 ruleset ssh_commands_inside direction 'in'
165: access list rule, action permit
165: filtering rule: access list ssh_commands_inside, action permit
166: Interface Ethernet0.101 ruleset ssh_commands_outside direction 'in'
166: access list rule, action permit
166: filtering rule: access list ssh_commands_outside, action permit
+1 -1
View File
@@ -55,8 +55,8 @@ DEPENDPATH = ../../common \
STATIC_LIBS += \
../main/libtest_main.a \
../../import/libimport.a \
../../libgui/libgui.a \
../../import/libimport.a \
../../common/libcommon.a \
../../iptlib/libiptlib.a \
../../pflib/libfwbpf.a \