Subversion Repositories ALCASAR

Compare Revisions

Ignore whitespace Rev 567 → Rev 568

/scripts/alcasar-iptables.sh
1,11 → 1,13
#!/bin/sh
# $Id$
# script de mise en place des regles du parefeu d'Alcasar (mode normal)
# Script de mise en place des regles du parefeu d'Alcasar (mode normal)
# This script write the netfilter rules for ALCASAR
# Rexy - 3abtux - CPN
# there are three channels for log :
# There are three channels for log :
# 1 (default) for tracability;
# 2 for secure admin (ssh);
# 3 for exterior access attempts.
# The French Security Agency (ANSSI) rules was applied by 'alcasar.sh' script
 
IPTABLES="/sbin/iptables"
PROTO_FILTERING="no"
239,8 → 241,5
# Save all rules
/etc/init.d/iptables save
 
# no martians log (for mdv2009 only)
echo 0 > /proc/sys/net/ipv4/conf/all/log_martians
 
# End of script
 
/scripts/sbin/alcasar-bl.sh
53,6 → 53,7
$SED "s?.*?address=/&/$IP_RETOUR?g" /tmp/dnsmasq-bl.tmp
mv /tmp/dnsmasq-bl.tmp $DIR_DNS_FILTER_AVAILABLE/$DOMAINE.conf
done
echo
}
 
# Permet d'activer/désactiver les catégories de la BL