| 1 | #!/bin/sh |
|---|
| 2 | |
|---|
| 3 | $Id: bridge.ini,v 1.2 2005/02/05 15:37:29 thomasez Exp $ |
|---|
| 4 | |
|---|
| 5 | . /etc/functions.inc |
|---|
| 6 | . /etc/config |
|---|
| 7 | |
|---|
| 8 | hostname ${HOSTNAME} |
|---|
| 9 | |
|---|
| 10 | echo "0" > /proc/sys/net/ipv4/ip_forward |
|---|
| 11 | |
|---|
| 12 | ( ifconfig $INSIDE_DEV > /dev/null 2> /dev/null) || { |
|---|
| 13 | echo |
|---|
| 14 | echo "WARNING" |
|---|
| 15 | echo "Could not find two ethernet devices" |
|---|
| 16 | echo |
|---|
| 17 | exit; |
|---|
| 18 | } |
|---|
| 19 | |
|---|
| 20 | ( ifconfig $OUTSIDE_DEV > /dev/null 2> /dev/null) || { |
|---|
| 21 | echo |
|---|
| 22 | echo "WARNING" |
|---|
| 23 | echo "Could not find two ethernet devices" |
|---|
| 24 | echo |
|---|
| 25 | exit; |
|---|
| 26 | } |
|---|
| 27 | |
|---|
| 28 | if [ -f /mnt/config/open.lst ] |
|---|
| 29 | then |
|---|
| 30 | stripcr /mnt/config/open.lst /etc/open.lst |
|---|
| 31 | else |
|---|
| 32 | stripcr /mnt/tmp/open.lst /etc/open.lst |
|---|
| 33 | fi |
|---|
| 34 | |
|---|
| 35 | |
|---|
| 36 | # |
|---|
| 37 | # Adding the modules here: |
|---|
| 38 | # |
|---|
| 39 | |
|---|
| 40 | modprobe bridge > $DEBUG_LOG 2>&1 |
|---|
| 41 | modprobe ebtables > $DEBUG_LOG 2>&1 |
|---|
| 42 | modprobe ebtable_broute > $DEBUG_LOG 2>&1 |
|---|
| 43 | modprobe ebtable_filter > $DEBUG_LOG 2>&1 |
|---|
| 44 | modprobe ebtable_nat > $DEBUG_LOG 2>&1 |
|---|
| 45 | modprobe ebt_802_3 > $DEBUG_LOG 2>&1 |
|---|
| 46 | modprobe ebt_arp > $DEBUG_LOG 2>&1 |
|---|
| 47 | modprobe ebt_ip > $DEBUG_LOG 2>&1 |
|---|
| 48 | modprobe ebt_log > $DEBUG_LOG 2>&1 |
|---|
| 49 | modprobe ebt_mark > $DEBUG_LOG 2>&1 |
|---|
| 50 | modprobe ebt_mark_m > $DEBUG_LOG 2>&1 |
|---|
| 51 | modprobe ebt_pkttype > $DEBUG_LOG 2>&1 |
|---|
| 52 | |
|---|
| 53 | |
|---|
| 54 | brctl addbr br0 # create bridge interface |
|---|
| 55 | # brctl stp br0 off # disable spanning tree protocol on br0 |
|---|
| 56 | brctl addif br0 $OUTSIDE_DEV # add outside device to br0 |
|---|
| 57 | brctl addif br0 $INSIDE_DEV # add inside device to br0 |
|---|
| 58 | |
|---|
| 59 | ifconfig $OUTSIDE_DEV up |
|---|
| 60 | ifconfig $INSIDE_DEV up |
|---|
| 61 | ifconfig br0 up |
|---|
| 62 | |
|---|
| 63 | ############################################################### |
|---|
| 64 | # Set default policy |
|---|
| 65 | # |
|---|
| 66 | ebtables -P INPUT ACCEPT |
|---|
| 67 | ebtables -P OUTPUT ACCEPT |
|---|
| 68 | ebtables -P FORWARD ACCEPT |
|---|
| 69 | # clear existing tables |
|---|
| 70 | ebtables -F |
|---|
| 71 | ebtables -t nat -F |
|---|
| 72 | ebtables -t broute -F |
|---|
| 73 | |
|---|
| 74 | # |
|---|
| 75 | # Firewall rules: |
|---|
| 76 | # |
|---|
| 77 | |
|---|
| 78 | # |
|---|
| 79 | # Flushing the chains. |
|---|
| 80 | # |
|---|
| 81 | |
|---|
| 82 | iptables -F |
|---|
| 83 | for i in `cat /proc/net/ip_tables_names`; do iptables -F -t $i ; done |
|---|
| 84 | iptables -X |
|---|
| 85 | iptables -Z # zero all counters |
|---|
| 86 | |
|---|
| 87 | # |
|---|
| 88 | # Policy for chains DROP everything |
|---|
| 89 | # |
|---|
| 90 | iptables -P INPUT DROP |
|---|
| 91 | iptables -P OUTPUT DROP |
|---|
| 92 | iptables -P FORWARD DROP |
|---|
| 93 | |
|---|
| 94 | # Make sure NEW tcp connections are SYN packets |
|---|
| 95 | iptables -A INPUT -i $OUTSIDE_DEV -p tcp ! --syn -m state --state NEW -j DROP |
|---|
| 96 | |
|---|
| 97 | echo "Opening ports." |
|---|
| 98 | while read myline |
|---|
| 99 | do |
|---|
| 100 | case $myline in |
|---|
| 101 | \#*) |
|---|
| 102 | ;; |
|---|
| 103 | *) |
|---|
| 104 | if [ "$myline" != "" ] |
|---|
| 105 | then |
|---|
| 106 | YOURLINE=`echo $myline | sed -e 's/,/ /'` |
|---|
| 107 | set -- $YOURLINE |
|---|
| 108 | if [ "$1" -a "$2" ] |
|---|
| 109 | then |
|---|
| 110 | echo "$1:$2" |
|---|
| 111 | iptables -A FORWARD -p TCP -d $1 --dport $2 -j ACCEPT |
|---|
| 112 | iptables -A FORWARD -p UDP -d $1 --dport $2 -j ACCEPT |
|---|
| 113 | fi |
|---|
| 114 | fi |
|---|
| 115 | ;; |
|---|
| 116 | esac |
|---|
| 117 | done < /etc/open.lst |
|---|
| 118 | |
|---|
| 119 | # |
|---|
| 120 | # We don't like the NetBIOS and Samba leaking.. |
|---|
| 121 | # We don't really need these lines since the policy is drop but it's |
|---|
| 122 | # so important I'll keep it. |
|---|
| 123 | # |
|---|
| 124 | iptables -A FORWARD -p TCP --dport 135:139 -j DROP |
|---|
| 125 | iptables -A FORWARD -p UDP --dport 137:139 -j DROP |
|---|
| 126 | iptables -A FORWARD -p TCP --dport 445 -j DROP |
|---|
| 127 | iptables -A FORWARD -p UDP --dport 445 -j DROP |
|---|
| 128 | |
|---|
| 129 | # |
|---|
| 130 | # Keep state and open up for outgoing connections. |
|---|
| 131 | # |
|---|
| 132 | iptables -A FORWARD -m state --state NEW -i ${INSIDE_DEV} -j ACCEPT |
|---|
| 133 | iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT |
|---|
| 134 | iptables -A FORWARD -m state --state NEW,INVALID -i ${OUTSIDE_DEV} -j DROP |
|---|
| 135 | |
|---|
| 136 | echo "1" > /proc/sys/net/ipv4/ip_forward |
|---|
| 137 | |
|---|