#
# Shorewall version 4.0 - Sample Rules File for two-interface configuration.
# Copyright (C) 2006,2007 by the Shorewall Team
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
# License as published by the Free Software Foundation; either
# version 2.1 of the License, or (at your option) any later version.
#
# See the file README.txt for further details.
#------------------------------------------------------------------------------
# For information about entries in this file, type "man shorewall-rules"
######################################################################################################################################################################################################
#ACTION			SOURCE			DEST		PROTO		DEST		SOURCE		ORIGINAL	RATE		USER/	MARK	CONNLIMIT	TIME		HEADERS			SWITCH			HELPER
#								PORT		PORT(S)		DEST		LIMIT		GROUP
#SECTION ALL
#SECTION ESTABLISHED
#SECTION RELATED
?SECTION INVALID
# Don't allow connection pickup from the net
Invalid(DROP):$WARN		net			all		tcp

#SECTION UNTRACKED
?SECTION NEW

# Allow for the time being icmp types 3.x,8,11
#AllowICMPs(ACCEPT):none!	loc			$FW
#AllowICMPs(ACCEPT):none!	$FW			net
#AllowICMPs(ACCEPT):none!	$FW			vpn

# Drop all sort off Broadcast addresses and don't log them
Broadcast(DROP):none!	net			$FW
Broadcast(DROP):none!	$FW			net

# Accept DNS connections from the firewall to the network
DNS(ACCEPT):none!	loc			$FW
DNS(ACCEPT):none!	$FW			net
DNS(ACCEPT):none!	$FW			vpn
DNS(DROP):$INFO		net			$FW

# This rule silently drops Late DNS UDP replies on port 53
DropDNSrep(DROP):$INFO	net			$FW

# This rule silently drops UPnP probes on UDP port 1900
DropUPnP(DROP):$WARN	loc			$FW
DropUPnP(DROP):$WARN	$FW			net
DropUPnP(DROP):$WARN	net			$FW
DropUPnP(DROP):$WARN	$FW			loc

# Drop all sort off multicast addresses and don't log them
DropSmurfs:none!	net			$FW	
DropSmurfs:none!	$FW			net	

# handles Internet Radio Port 8000 (Protocol) traffic
IRP(ACCEPT):none!	loc			$FW			
IRP(ACCEPT):none!	$FW			net

# handles FTP traffic
FTP(ACCEPT):none!	loc			$FW
FTP(ACCEPT):none!	$FW			net
FTP(ACCEPT):none!	$FW			vpn
FTP(DROP):$WARN		net			$FW
FTP(DROP):$WARN		$FW			loc

# handles Git traffic
Git(ACCEPT):none!	loc			$FW
Git(ACCEPT):none!	$FW			net
Git(DROP):$WARN		net			$FW
Git(DROP):$WARN		$FW			loc

# handles plaintext HTTP (WWW) traffic
HTTP(ACCEPT):none!	loc			$FW			
HTTP(ACCEPT):none!	$FW			net
HTTP(ACCEPT):none!	$FW			vpn
HTTP(DROP):$WARN	net			$FW	

# handles HTTPS (WWW over SSL) traffic
HTTPS(ACCEPT):none!	loc			$FW
HTTPS(ACCEPT):none!	$FW			net
HTTPS(ACCEPT):none!	$FW			vpn
HTTPS(DROP):$WARN	net			$FW
HTTPS(DROP):$WARN	$FW			loc

# handles encrypted IMAP traffic
IMAPS(ACCEPT):none!	loc			$FW
IMAPS(ACCEPT):none!	$FW			net
IMAPS(DROP):$WARN	net			$FW
IMAPS(DROP):$WARN	$FW			loc

# handles NTP protocol
NTP(ACCEPT):none!	loc			$FW
NTP(ACCEPT):none!	$FW			net
NTP(DROP):$WARN		net			$FW
NTP(DROP):$WARN		$FW			loc

# handles HTTPS (WWW over SSL:port 888) traffic
PASSEREL(ACCEPT):none!	loc			$FW
PASSEREL(ACCEPT):none!	$FW			net

# Allow / Disallow Ping from / to the local network
Ping(ACCEPT):none!	loc			$FW
Ping(ACCEPT):none!	$FW			net
Ping(ACCEPT):none!	$FW			vpn
Ping(DROP):$WARN	$FW			loc
Ping(DROP):$WARN	net			$FW

# handles Microsoft RDP (Remote Desktop) traffic
RDP(ACCEPT):none!	loc			$FW
RDP(ACCEPT):none!	$FW			vpn

# handles plaintext POP3 traffic
POP3(DROP):$WARN	loc			$FW
POP3(DROP):$WARN	$FW			net
POP3(DROP):$WARN	net			$FW
POP3(DROP):$WARN	$FW			loc

# handles encrypted POP3s traffic
POP3S(DROP):$WARN	loc			$FW
POP3S(DROP):$WARN	$FW			net
POP3S(DROP):$WARN	net			$FW
POP3S(DROP):$WARN	$FW			loc

# handles download Rsync traffic
Rsync(ACCEPT):none!	loc			$FW
Rsync(ACCEPT):none!	$FW			net

# handles encrypted SMTPS (email) traffic
SMTPS(ACCEPT):none!	loc			$FW
SMTPS(ACCEPT):none!	$FW			net
SMTPS(DROP):$WARN	net			$FW
SMTPS(DROP):$WARN	$FW			loc

# handles unencrypted SMTPS (email) traffic
SMTP(DROP):$WARN	loc			$FW
SMTP(DROP):$WARN	$FW			net
SMTP(DROP):$WARN	net			$FW
SMTP(DROP):$WARN	$FW			loc

# Accept VPNC connections from the firewall over het network to work
VPNC(ACCEPT):none!	loc			$FW
VPNC(ACCEPT):none!	$FW			vpn

# handles whois (nicname) traffic
Whois(ACCEPT):none!	loc			$FW
Whois(ACCEPT):none!	$FW			net
Whois(ACCEPT):none!	$FW			vpn
Whois(DROP):$WARN	net			$FW
Whois(DROP):$WARN	$FW			loc

DROP:$WARN		net			$FW		icmp	any
DROP:$WARN		loc			$FW		tcp	0:65535
DROP:$WARN		loc			$FW		udp	0:65535
DROP:$WARN		$FW			net		tcp	0:65535
DROP:$WARN		$FW			net		udp	0:65535
DROP:$WARN		net			$FW		tcp	0:65535
DROP:$WARN		net			$FW		udp	0:65535
DROP:$WARN		$FW			loc		tcp	0:65535
DROP:$WARN		$FW			loc		udp	0:65535
#
