Index: macro.L2TP =================================================================== --- macro.L2TP (revision 7569) +++ macro.L2TP (working copy) @@ -6,8 +6,8 @@ # This macro (bidirectional) handles Layer 2 Tunneling Protocol traffic (RFC 2661) # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 1701 # L2TP PARAM DEST SOURCE udp 1701 # L2TP #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.DNS =================================================================== --- macro.DNS (revision 7569) +++ macro.DNS (working copy) @@ -6,8 +6,8 @@ # This macro handles DNS traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 53 PARAM - - tcp 53 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.NTPbrd =================================================================== --- macro.NTPbrd (revision 7569) +++ macro.NTPbrd (working copy) @@ -11,8 +11,8 @@ # Netfilter doesn't track connections for broadcast traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 123 PARAM - - udp 1024: 123 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Auth =================================================================== --- macro.Auth (revision 7569) +++ macro.Auth (working copy) @@ -6,7 +6,7 @@ # This macro handles Auth (identd) traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 113 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.IPIP =================================================================== --- macro.IPIP (revision 7569) +++ macro.IPIP (working copy) @@ -6,8 +6,8 @@ # This macro (bidirectional) handles IPIP capsulation traffic # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - 94 # IPIP PARAM DEST SOURCE 94 # IPIP #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.IPsec =================================================================== --- macro.IPsec (revision 7569) +++ macro.IPsec (working copy) @@ -6,8 +6,8 @@ # This macro (bidirectional) handles IPsec traffic # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 500 500 # IKE PARAM - - 50 # ESP PARAM DEST SOURCE udp 500 500 # IKE Index: macro.AllowICMPs =================================================================== --- macro.AllowICMPs (revision 7569) +++ macro.AllowICMPs (working copy) @@ -6,8 +6,8 @@ # This macro ACCEPTs needed ICMP types # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP ACCEPT - - icmp fragmentation-needed ACCEPT - - icmp time-exceeded #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.TFTP =================================================================== --- macro.TFTP (revision 7569) +++ macro.TFTP (working copy) @@ -8,7 +8,7 @@ # Internet. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 69 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.SixXS =================================================================== --- macro.SixXS (revision 7569) +++ macro.SixXS (working copy) @@ -6,7 +6,7 @@ # This macro handles SixXS -- An IPv6 Deployment and Tunnel Broken # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE RATE USER/ +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ # PORT PORT(S) LIMIT GROUP PARAM - - tcp 3874 # Used for retrieving the tunnel information (eg by AICCU) PARAM - - udp 3740 # Used for signaling where the current IPv4 endpoint Index: macro.IPPserver =================================================================== --- macro.IPPserver (revision 7569) +++ macro.IPPserver (working copy) @@ -4,7 +4,7 @@ # /usr/share/shorewall/macro.IPPserver # # This macro handles Internet Printing Protocol (IPP), indicating -# that DEST is a printing server for SOURCE. The macro allows +# that is a printing server for SOURCE. The macro allows # print queue broadcasts from the server to the client, and # printing connections from the client to the server. # @@ -23,8 +23,8 @@ # IPPserver/ACCEPT $FW loc # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM SOURCE DEST tcp 631 PARAM DEST SOURCE udp 631 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.HTTP =================================================================== --- macro.HTTP (revision 7569) +++ macro.HTTP (working copy) @@ -6,7 +6,7 @@ # This macro handles plaintext HTTP (WWW) traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 80 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.LDAP =================================================================== --- macro.LDAP (revision 7569) +++ macro.LDAP (working copy) @@ -11,7 +11,7 @@ # Consult your LDAP server documentation for details. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 389 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Amanda =================================================================== --- macro.Amanda (revision 7569) +++ macro.Amanda (working copy) @@ -8,8 +8,8 @@ # files from those nodes. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 10080 # # You may also need this rule. With AMANDA 2.4.4 on Linux kernel 2.6, Index: macro.JabberSecure =================================================================== --- macro.JabberSecure (revision 7569) +++ macro.JabberSecure (working copy) @@ -6,7 +6,7 @@ # This macro accepts Jabber traffic (plaintext). # ############################################################################### -#TARGET SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#TARGET SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 5222 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Trcrt =================================================================== --- macro.Trcrt (revision 7569) +++ macro.Trcrt (working copy) @@ -6,8 +6,8 @@ # This macro handles Traceroute (for up to 30 hops). # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 33434:33524 # UDP Traceroute PARAM - - icmp 8 # ICMP Traceroute #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.NNTPS =================================================================== --- macro.NNTPS (revision 7569) +++ macro.NNTPS (working copy) @@ -7,7 +7,7 @@ # plaintext NNTP, see macro.NNTP. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 563 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.SPAMD =================================================================== --- macro.SPAMD (revision 7569) +++ macro.SPAMD (working copy) @@ -6,7 +6,7 @@ # This macro handles Spam Assassin SPAMD traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 783 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Distcc =================================================================== --- macro.Distcc (revision 7569) +++ macro.Distcc (working copy) @@ -6,7 +6,7 @@ # This macro handles connections to the Distributed Compiler service. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 3632 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.GRE =================================================================== --- macro.GRE (revision 7569) +++ macro.GRE (working copy) @@ -6,8 +6,8 @@ # This macro (bi-directional) handles Generic Routing Encapsulation traffic (RFC 1701) # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - 47 # GRE PARAM DEST SOURCE 47 # GRE #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Syslog =================================================================== --- macro.Syslog (revision 7569) +++ macro.Syslog (working copy) @@ -6,7 +6,7 @@ # This macro handles syslog UDP traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 514 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.POP3 =================================================================== --- macro.POP3 (revision 7569) +++ macro.POP3 (working copy) @@ -7,7 +7,7 @@ # see macro.POP3S. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 110 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.RDP =================================================================== --- macro.RDP (revision 7569) +++ macro.RDP (working copy) @@ -6,7 +6,7 @@ # This macro handles Microsoft RDP (Remote Desktop) traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 3389 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.IMAP =================================================================== --- macro.IMAP (revision 7569) +++ macro.IMAP (working copy) @@ -7,7 +7,7 @@ # see macro.IMAPS. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 143 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.FTP =================================================================== --- macro.FTP (revision 7569) +++ macro.FTP (working copy) @@ -6,7 +6,7 @@ # This macro handles FTP traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 21 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.BitTorrent =================================================================== --- macro.BitTorrent (revision 7569) +++ macro.BitTorrent (working copy) @@ -6,8 +6,8 @@ # This macro handles BitTorrent traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 6881:6889 # # It may also be necessary to allow UDP traffic: Index: macro.Time =================================================================== --- macro.Time (revision 7569) +++ macro.Time (working copy) @@ -8,7 +8,7 @@ # you shouldn't be using this. NTP is a superior alternative. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 37 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.NTP =================================================================== --- macro.NTP (revision 7569) +++ macro.NTP (working copy) @@ -7,7 +7,7 @@ # For broadcast NTP traffic, use NTPbrd Macro. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 123 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.SMTPS =================================================================== --- macro.SMTPS (revision 7569) +++ macro.SMTPS (working copy) @@ -11,7 +11,7 @@ # the POP3(S) or IMAP(S) macros. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 465 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.DropUPnP =================================================================== --- macro.DropUPnP (revision 7569) +++ macro.DropUPnP (working copy) @@ -6,7 +6,7 @@ # This macro silently drops UPnP probes on UDP port 1900 # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP DROP - - udp 1900 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Telnets =================================================================== --- macro.Telnets (revision 7569) +++ macro.Telnets (working copy) @@ -7,7 +7,7 @@ # For traffic over the internet, SSH might be more practical. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 992 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.SMBswat =================================================================== --- macro.SMBswat (revision 7569) +++ macro.SMBswat (working copy) @@ -7,7 +7,7 @@ # (SWAT). # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 901 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Jabberd =================================================================== --- macro.Jabberd (revision 7569) +++ macro.Jabberd (working copy) @@ -6,7 +6,7 @@ # This macro accepts Jabber traffic (ssl). # ############################################################################### -#TARGET SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#TARGET SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 5223 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Telnet =================================================================== --- macro.Telnet (revision 7569) +++ macro.Telnet (working copy) @@ -7,7 +7,7 @@ # internet, telnet is inappropriate; use SSH instead # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 23 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.SSH =================================================================== --- macro.SSH (revision 7569) +++ macro.SSH (working copy) @@ -6,7 +6,7 @@ # This macro handles secure shell (SSH) traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 22 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.HTTPS =================================================================== --- macro.HTTPS (revision 7569) +++ macro.HTTPS (working copy) @@ -6,7 +6,7 @@ # This macro handles HTTPS (WWW over SSL) traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 443 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.IPsecnat =================================================================== --- macro.IPsecnat (revision 7569) +++ macro.IPsecnat (working copy) @@ -6,8 +6,8 @@ # This macro (bidirectional) handles IPsec traffic and Nat-Traversal # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 500 # IKE PARAM - - udp 4500 # NAT-T PARAM - - 50 # ESP Index: macro.IMAPS =================================================================== --- macro.IMAPS (revision 7569) +++ macro.IMAPS (working copy) @@ -7,7 +7,7 @@ # (not recommended), see macro.IMAP. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 993 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.DropDNSrep =================================================================== --- macro.DropDNSrep (revision 7569) +++ macro.DropDNSrep (working copy) @@ -6,7 +6,7 @@ # This macro silently drops DNS UDP replies # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP DROP - - udp - 53 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.SMTP =================================================================== --- macro.SMTP (revision 7569) +++ macro.SMTP (working copy) @@ -14,7 +14,7 @@ # the POP3 or IMAP macros. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 25 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.VNC =================================================================== --- macro.VNC (revision 7569) +++ macro.VNC (working copy) @@ -6,7 +6,7 @@ # This macro handles VNC traffic for VNC display's 0 - 9. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 5900:5909 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.IPP =================================================================== --- macro.IPP (revision 7569) +++ macro.IPP (working copy) @@ -6,7 +6,7 @@ # This macro handles Internet Printing Protocol (IPP). # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 631 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Edonkey =================================================================== --- macro.Edonkey (revision 7569) +++ macro.Edonkey (working copy) @@ -28,8 +28,8 @@ # applications such as aMule WebServer or aMuleCMD. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 4662 PARAM - - udp 4665 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Rsync =================================================================== --- macro.Rsync (revision 7569) +++ macro.Rsync (working copy) @@ -6,7 +6,7 @@ # This macro handles connections to the rsync server. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 873 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Rdate =================================================================== --- macro.Rdate (revision 7569) +++ macro.Rdate (working copy) @@ -10,7 +10,7 @@ # use Time macro instead. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 37 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.LDAPS =================================================================== --- macro.LDAPS (revision 7569) +++ macro.LDAPS (working copy) @@ -11,7 +11,7 @@ # Consult your LDAP server documentation for details. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 636 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.PCA =================================================================== --- macro.PCA (revision 7569) +++ macro.PCA (working copy) @@ -6,8 +6,8 @@ # This macro handles PCAnywere (tm) # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 5632 PARAM - - tcp 5631 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Finger =================================================================== --- macro.Finger (revision 7569) +++ macro.Finger (working copy) @@ -7,7 +7,7 @@ # your finger information to internet. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 79 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.SMB =================================================================== --- macro.SMB (revision 7569) +++ macro.SMB (working copy) @@ -10,8 +10,8 @@ # between hosts you fully trust. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 135,445 PARAM - - udp 137:139 PARAM - - udp 1024: 137 Index: macro.VNCL =================================================================== --- macro.VNCL (revision 7569) +++ macro.VNCL (working copy) @@ -7,7 +7,7 @@ # mode. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 5500 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Gnutella =================================================================== --- macro.Gnutella (revision 7569) +++ macro.Gnutella (working copy) @@ -6,8 +6,8 @@ # This macro handles Gnutella traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 6346 PARAM - - udp 6346 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Jetdirect =================================================================== --- macro.Jetdirect (revision 7569) +++ macro.Jetdirect (working copy) @@ -6,7 +6,7 @@ # This macro handles HP Jetdirect printing. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 9100 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Webmin =================================================================== --- macro.Webmin (revision 7569) +++ macro.Webmin (working copy) @@ -6,7 +6,7 @@ # This macro handles Webmin traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 10000 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Whois =================================================================== --- macro.Whois (revision 7569) +++ macro.Whois (working copy) @@ -6,7 +6,7 @@ # This macro handles whois (nicname) traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 43 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.CVS =================================================================== --- macro.CVS (revision 7569) +++ macro.CVS (working copy) @@ -6,7 +6,7 @@ # This macro handles connections to the CVS pserver. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 2401 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Submission =================================================================== --- macro.Submission (revision 7569) +++ macro.Submission (working copy) @@ -6,7 +6,7 @@ # This macro handles mail message submission traffic. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 587 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Drop =================================================================== --- macro.Drop (revision 7569) +++ macro.Drop (working copy) @@ -11,8 +11,8 @@ # Drop net all # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP # # Don't log 'auth' REJECT # Index: macro.POP3S =================================================================== --- macro.POP3S (revision 7569) +++ macro.POP3S (working copy) @@ -7,7 +7,7 @@ # see macro.POP3. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 995 # Secure POP3 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.MySQL =================================================================== --- macro.MySQL (revision 7569) +++ macro.MySQL (working copy) @@ -6,7 +6,7 @@ # This macro handles connections to the MySQL server. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 3306 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.SVN =================================================================== --- macro.SVN (revision 7569) +++ macro.SVN (working copy) @@ -7,7 +7,7 @@ # # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 3690 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.JabberPlain =================================================================== --- macro.JabberPlain (revision 7569) +++ macro.JabberPlain (working copy) @@ -6,7 +6,7 @@ # This macro accepts Jabberd intercommunication traffic # ############################################################################### -#TARGET SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#TARGET SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 5269 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.ICQ =================================================================== --- macro.ICQ (revision 7569) +++ macro.ICQ (working copy) @@ -6,7 +6,7 @@ # This macro handles ICQ, now called AOL Instant Messenger (or AIM). # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 5190 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Reject =================================================================== --- macro.Reject (revision 7569) +++ macro.Reject (working copy) @@ -12,8 +12,8 @@ # # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP # # Don't log 'auth' REJECT # Index: macro.SNMP =================================================================== --- macro.SNMP (revision 7569) +++ macro.SNMP (working copy) @@ -6,8 +6,8 @@ # This macro handles SNMP traffic (including traps). # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 161:162 PARAM - - tcp 161 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Web =================================================================== --- macro.Web (revision 7569) +++ macro.Web (working copy) @@ -8,8 +8,8 @@ # is recommended. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 80 # HTTP (plaintext) PARAM - - tcp 443 # HTTPS (over SSL) #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.NNTP =================================================================== --- macro.NNTP (revision 7569) +++ macro.NNTP (working copy) @@ -7,7 +7,7 @@ # encrypted NNTP, see macro.NNTPS. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 119 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.Printer =================================================================== --- macro.Printer (revision 7569) +++ macro.Printer (working copy) @@ -6,7 +6,7 @@ # This macro handles Line Printer protocol printing. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 515 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.SMBBI =================================================================== --- macro.SMBBI (revision 7569) +++ macro.SMBBI (working copy) @@ -10,8 +10,8 @@ # allow SMB traffic between hosts you fully trust. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 135,445 PARAM - - udp 137:139 PARAM - - udp 1024: 137 Index: macro.Ping =================================================================== --- macro.Ping (revision 7569) +++ macro.Ping (working copy) @@ -6,7 +6,7 @@ # This macro handles 'ping' requests. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - icmp 8 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.PostgreSQL =================================================================== --- macro.PostgreSQL (revision 7569) +++ macro.PostgreSQL (working copy) @@ -6,7 +6,7 @@ # This macro handles connections to the PostgreSQL server. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - tcp 5432 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Index: macro.IPsecah =================================================================== --- macro.IPsecah (revision 7569) +++ macro.IPsecah (working copy) @@ -7,8 +7,8 @@ # This is insecure. You should use ESP with encryption for security. # ############################################################################### -#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ -# PORT PORT(S) DEST LIMIT GROUP +#ACTION SOURCE PROTO DEST SOURCE RATE USER/ +# PORT PORT(S) LIMIT GROUP PARAM - - udp 500 500 # IKE PARAM - - 51 # AH PARAM DEST SOURCE udp 500 500 # IKE