Configuration of the “/etc/rc.d/init.d/firewall” script file for the Mail Server
# Reject, rather than deny, the incoming auth port. (NET-3-H0WT0)
ipchains -A input -i $EXTERNAL_INTERFACE -p tcp \ -s $ANYWHERE \ -d $IPADDR 113 -j REJECT
#SYSLOG server (514)
#
# Provides full remote logging. Using this feature you’re able to
# control all syslog messages on one host.
# ipchains -A input -i $EXTERNAL_INTERFACE -p udp \
# -s $SYSLOG_CLIENT \
# -d$IPADDR 514-j ACCEPT
# SYSLOG client (514)
# ipchains -A output -i $EXTERNAL_INTERFACE -p udp \
# -s$IPADDR514\
# -d $SYSLOG_SERVER 514 -j ACCEPT
# SMTP server (25)
ipchains -A input -i $EXTERNAL_INTERFACE -p tcp \ -s $ANYWHERE $UNPRIVPORTS \ -d $IPADDR 25 -j ACCEPT
ipchains -A output -i $EXTERNAL_INTERFACE -p tcp ! -y \ -s $IPADDR 25 \ -d $ANYWHERE $UNPRIVPORTS -j ACCEPT
# SMTP client (25)
#
ipchains -A input -i $EXTERNAL_INTERFACE -p tcp ! -y \ -s $ANYWHERE 25 \ -d $IPADDR $UNPRIVPORTS -j ACCEPT
ipchains -A output -i $EXTERNAL_INTERFACE -p tcp \ -s $IPADDR $UNPRIVPORTS \ -d $ANYWHERE 25 -j ACCEPT
#IMAP server (143)
#
ipchains -A input -i $EXTERNAL_INTERFACE -p tcp \ -s $ANYWHERE $UNPRIVPORTS \ -d $IPADDR 143 -j ACCEPT
ipchains -A output -i $EXTERNAL_INTERFACE -p tcp ! -y \ -s$IPADDR143\ -d $ANYWHERE $UNPRIVPORTS -j ACCEPT
# POP server (110)
#
Страниц: 1 2 3 4 5 6 7 8 9 10 11