Browse Source

archivo: update rules after bonding interfaces

Maximilian Ronniger 2 years ago
parent
commit
db4d28deee
1 changed files with 45 additions and 11 deletions
  1. 45 11
      dpFirewalls.fwb

+ 45 - 11
dpFirewalls.fwb

@@ -1161,7 +1161,7 @@
     </Firewall>
     <AddressRange id="id6999X40322" name="DP Net LAN Linux Servers" comment="" ro="False" start_address="10.0.21.1" end_address="10.0.21.10"/>
   </Library>
-  <Library id="id1592X15287" color="#d2ffd0" name="User" comment="" ro="False">
+  <Library id="id1592X15287" color="#000100" name="User" comment="" ro="False">
     <ObjectGroup id="id1593X15287" name="Objects" comment="" ro="False">
       <ObjectGroup id="id1594X15287" name="Addresses" comment="" ro="False">
         <IPv4 id="id6067X15287" name="Internet Prodcast" comment="" ro="False" address="10.0.1.255" netmask="0.0.0.0"/>
@@ -1196,7 +1196,7 @@
       <ServiceGroup id="id1609X15287" name="TagServices" comment="" ro="False"/>
     </ServiceGroup>
     <ObjectGroup id="id1610X15287" name="Firewalls" comment="" ro="False">
-      <Firewall id="id2327X15287" host_OS="linux24" lastCompiled="1573816440" lastInstalled="1559914159" lastModified="1573816401" platform="iptables" name="archivo" comment="" ro="False">
+      <Firewall id="id2327X15287" host_OS="linux24" lastCompiled="1699015800" lastInstalled="1699015806" lastModified="1699015795" platform="iptables" name="archivo" comment="" ro="False">
         <NAT id="id2331X15287" name="NAT" comment="" ro="False" ipv4_rule_set="False" ipv6_rule_set="False" top_rule_set="True">
           <NATRule id="id6818X40322" disabled="False" group="" position="0" action="Translate" comment="">
             <OSrc neg="False">
@@ -1522,12 +1522,12 @@
         <Routing id="id2333X15287" name="Routing" comment="" ro="False" ipv4_rule_set="False" ipv6_rule_set="False" top_rule_set="True">
           <RuleSetOptions/>
         </Routing>
-        <Interface id="id2335X15287" dedicated_failover="False" dyn="False" label="lan" security_level="100" unnum="False" unprotected="False" name="eth0" comment="" ro="False">
-          <IPv4 id="id2336X15287" name="archivo:eth0:ip" comment="" ro="False" address="10.0.21.2" netmask="255.255.255.0"/>
+        <Interface id="id2335X15287" dedicated_failover="False" dyn="False" label="lan" mgmt="True" security_level="100" unnum="False" unprotected="False" name="vlan1" comment="" ro="False">
+          <IPv4 id="id2336X15287" name="archivo:vlan1:ip" comment="" ro="False" address="10.0.21.2" netmask="255.255.255.0"/>
           <InterfaceOptions/>
         </Interface>
-        <Interface id="id2337X15287" dedicated_failover="False" dyn="False" label="link" mgmt="False" security_level="100" unnum="False" unprotected="False" name="eth1" comment="" ro="False">
-          <IPv4 id="id2338X15287" name="archivo:eth1:ip" comment="" ro="False" address="10.0.2.2" netmask="255.255.255.252"/>
+        <Interface id="id2337X15287" dedicated_failover="False" dyn="False" label="link" mgmt="False" security_level="100" unnum="False" unprotected="False" name="vlan4" comment="" ro="False">
+          <IPv4 id="id2338X15287" name="archivo:vlan4:ip" comment="" ro="False" address="10.0.2.2" netmask="255.255.255.252"/>
           <InterfaceOptions/>
         </Interface>
         <Interface id="id8737X15287" dedicated_failover="False" dyn="False" label="loopback" mgmt="False" security_level="0" unnum="False" unprotected="False" name="lo" comment="" ro="False">
@@ -1536,7 +1536,7 @@
             <Option name="type">ethernet</Option>
           </InterfaceOptions>
         </Interface>
-        <Management address="10.0.2.2">
+        <Management address="10.0.21.2">
           <SNMPManagement enabled="False" snmp_read_community="" snmp_write_community=""/>
           <FWBDManagement enabled="False" identity="" port="-1"/>
           <PolicyInstallScript arguments="" command="" enabled="False"/>
@@ -1549,7 +1549,7 @@
           <Option name="add_mgmt_ssh_rule_when_stoped">False</Option>
           <Option name="add_rules_for_ipv6_neighbor_discovery">False</Option>
           <Option name="admUser">madhu</Option>
-          <Option name="altAddress">127.0.0.1</Option>
+          <Option name="altAddress">10.0.21.2</Option>
           <Option name="bridging_fw">False</Option>
           <Option name="check_shading">True</Option>
           <Option name="clamp_mss_to_mtu">False</Option>
@@ -1560,6 +1560,7 @@
           <Option name="configure_bridge_interfaces">False</Option>
           <Option name="configure_interfaces">True</Option>
           <Option name="configure_vlan_interfaces">False</Option>
+          <Option name="data_dir"/>
           <Option name="debug">False</Option>
           <Option name="drop_invalid">False</Option>
           <Option name="epilog_script"/>
@@ -1570,7 +1571,39 @@
           <Option name="ipv4_6_order">ipv4_first</Option>
           <Option name="limit_suffix"/>
           <Option name="limit_value">0</Option>
+          <Option name="linux24_accept_redirects"/>
+          <Option name="linux24_accept_source_route"/>
+          <Option name="linux24_conntrack_hashsize">0</Option>
+          <Option name="linux24_conntrack_max">0</Option>
+          <Option name="linux24_conntrack_tcp_be_liberal"/>
+          <Option name="linux24_icmp_echo_ignore_all"/>
+          <Option name="linux24_icmp_echo_ignore_broadcasts">1</Option>
+          <Option name="linux24_icmp_ignore_bogus_error_responses"/>
+          <Option name="linux24_ip_dynaddr"/>
           <Option name="linux24_ip_forward">1</Option>
+          <Option name="linux24_ipv6_forward">0</Option>
+          <Option name="linux24_log_martians">1</Option>
+          <Option name="linux24_path_brctl"/>
+          <Option name="linux24_path_ifenslave"/>
+          <Option name="linux24_path_ip">/usr/sbin/ip</Option>
+          <Option name="linux24_path_ip6tables"/>
+          <Option name="linux24_path_ip6tables_restore"/>
+          <Option name="linux24_path_ipset"/>
+          <Option name="linux24_path_iptables">/usr/sbin/iptables</Option>
+          <Option name="linux24_path_iptables_restore">/usr/sbin/iptables-restore</Option>
+          <Option name="linux24_path_logger"/>
+          <Option name="linux24_path_lsmod"/>
+          <Option name="linux24_path_modprobe"/>
+          <Option name="linux24_path_vconfig"/>
+          <Option name="linux24_rp_filter">1</Option>
+          <Option name="linux24_tcp_ecn"/>
+          <Option name="linux24_tcp_fack"/>
+          <Option name="linux24_tcp_fin_timeout">0</Option>
+          <Option name="linux24_tcp_keepalive_interval">0</Option>
+          <Option name="linux24_tcp_sack"/>
+          <Option name="linux24_tcp_syncookies"/>
+          <Option name="linux24_tcp_timestamps"/>
+          <Option name="linux24_tcp_window_scaling"/>
           <Option name="load_modules">True</Option>
           <Option name="local_nat">False</Option>
           <Option name="log_all">False</Option>
@@ -1588,14 +1621,15 @@
           <Option name="output_file"/>
           <Option name="prolog_place">top</Option>
           <Option name="prolog_script"/>
-          <Option name="scpArgs">-P 22211</Option>
+          <Option name="scpArgs"/>
           <Option name="script_name_on_firewall"/>
-          <Option name="sshArgs">-p 22211</Option>
+          <Option name="sshArgs"/>
           <Option name="ulog_cprange">0</Option>
           <Option name="ulog_nlgroup">1</Option>
           <Option name="ulog_qthreshold">1</Option>
           <Option name="use_ULOG">False</Option>
-          <Option name="use_iptables_restore">False</Option>
+          <Option name="use_iptables_restore">True</Option>
+          <Option name="use_kerneltz">False</Option>
           <Option name="use_m_set">False</Option>
           <Option name="use_numeric_log_levels">False</Option>
           <Option name="verify_interfaces">True</Option>