Jérémy Dubois
9898ff9e62
Put our IPs back in the TRUSTEDIPS variable
The TRUSTEDIPS variable is the public reference for Evolix IPs
2 weeks ago
Jérémy Lecour
80307172af
Remove volatile.debian.org from HTTPSITES
This domain doesn't exist anymore.
1 month ago
Jérémy Lecour
7126d70982
Update copyright and add version number
2 months ago
Gregory Colpart
5a907b1ce0
new policy for default ports: we close almost all to be sure that nothing works if we don't configure it
nouvelle politique d'ouverture des ports par défaut : on ferme quasi tout pour que rien ne marche ou presque si on ne configure rien
5 months ago
Jérémy Lecour
ba193f22fa
Change public SSH port from 2222 to 22222
6 months ago
Ludovic Poujol
7c384a777b
Better handling of Docker to match the usual minifirewall behaviour
Revert some changes from 0ec2cb2f4b
like the SERVICESTCP4 SERVICESUDP4
Instead, we'll re-create the usual behaviour of public, privileged and
trusted ports for docker when the variable DOCKER is set to "on"
7 months ago
Ludovic Poujol
0ec2cb2f4b
Make it compatible with docker
Add a new variable "DOCKER" that should be set to "on" when this is a
docker machine.
It will
- Disable the nat tables flush on stop/restart
Reason : Not breaking outgoing networking for containers
- Create the "DOCKER-USER" chain, and add a DROP
By default everything is closed and we don't expose services to the
outside world
- Add rules in the "DOCKER-USER" chain to open services to the outside
world.
Untested with swarm
1 year ago
Ludovic Poujol
30041b8949
Fix IPV6 var not being defined on stop
1 year ago
Romain Dessort
9ebb5fe748
Add security-cdn.debian.org to HTTPSITES whitelist
Debian migrated its security.debian.org repository to Fastly CDN
(security-cdn.debian.org) so we have to whitelist it too to make
security upgrades possible.
3 years ago
Jérémy Lecour
afdfc00a67
Add letsencrypt in HTTPSITES
3 years ago
Victor LABORIE
dba28b0679
Remove obsolete srv domain
4 years ago
Gregory Colpart
164d727e8e
Remove obsolete IP addr
5 years ago
Gregory Colpart
4ea10ccc83
Improve configuration file
5 years ago
Gregory Colpart
9579cfe991
Fix #1565 . Use now /etc/default/minifirewall for config file!
5 years ago
Gregory Colpart
6bc560b66a
Add default rule for IPv6 DNS responses
6 years ago
Benoît S.
283ff1161f
Added SpamAssassin update repo URLs.
6 years ago
Gregory Colpart
2d2fded0ac
use same syntax for all ip6tables rules
6 years ago
Benoît S.
ec0b8ffef5
Added to HTTPSITES zidane and antismap00.
6 years ago
Arnaud Tomeï
5525ff343f
Adding new IP address for Evolix
6 years ago
Gregory Colpart
d452c16bc6
Duplicate rule
6 years ago
Benoît S.
f3674af0db
Allow Input DNS on IPv6.
Used when a slave respond to a master notification in bind for example.
6 years ago
Benoît S.
5275f8d7e2
Moves rules from firewall.rc to minifirewall core.
6 years ago
Benoît S.
ce1d628516
Adding rules for DHCPv6.
7 years ago
Benoît S.
8ed3c722ce
Adding hwraid.le-vert.net in HTTPSITES
7 years ago
Benoît S.
6c162c516b
Fixing typo in HTTPSITES.
7 years ago
Gregory Colpart
6df7c86ccf
Add http://backports.debian.org by default
7 years ago
Gregory Colpart
7d3d928e02
Improve new UDP rules to DROP by default
8 years ago
Benoît S.
ec14ee9f3e
Last committer removed the IPv4 UDP rules?! Re-adding.
8 years ago
Gregory Colpart
f714700623
Allow SMTP IPv6
8 years ago
Romain Dessort
7795b715e6
Add rules to open traceroute UDP port.
8 years ago
Benoît S.
44bb5925eb
Amelioration added for blocking output UDP.
8 years ago
Benoît S.
b5412ce98a
Adding rules to block outgoing UDP trafic except for DNS and NTP.
8 years ago
Gregory Colpart
e7a7f26951
Patch to have compatibility with poor non-IPv6 server
9 years ago
Gregory Colpart
11ca1d1599
Improve rocks-solid comportment of the firewall script !
9 years ago
Gregory Colpart
94473ada72
Add a new default IP address
9 years ago
Gregory Colpart
14a220a546
We authorize now all NTP traffic by default
9 years ago
Gregory Colpart
1a17daeba4
Fix a bug with var name, and remove _ (uniformization)
9 years ago
Gregory Colpart
053f3d9c4e
Modify default NTP address
9 years ago
Gregory Colpart
a46b97845c
Allow all DNS requests by default
9 years ago
Gregory Colpart
27fe1213f5
Open HTTPS by default
10 years ago
Colin Darie
821af4d12f
Added a SMTP_SECURE_OK rule (port 465)
Signed-off-by: Gregory Colpart <reg@evolix.fr>
10 years ago
Colin Darie
9feded0d21
La directive INTIP n'est pas (plus?) utilisée
Signed-off-by: Gregory Colpart <reg@evolix.fr>
10 years ago
Romain Dessort
4a2e9813b5
Ajout de l'URL mirror.evolix.org dans la liste des sites autorisés.
10 years ago
Gregory Colpart
1cdb7af52c
Add a new IP in default configuration
10 years ago
Romain Dessort
530ed78833
Ajout de l'URL mirror.evolix.org dans la liste des sites autorisés.
10 years ago
Gregory Colpart
60b0b1c5d0
Improve default rules
11 years ago
Gregory Colpart
c3a66eb333
Add NEEDRESTRICT chain to deny some services by free rules
Somes improvements
11 years ago
Gregory Colpart
b3fb2ce6b9
Import files from http://www.gcolpart.com/hacks/
11 years ago