hcoop/zz_old/debian/hcoop-firewall-config.git
11 years agoAllow mail routing via smarthost
Clinton Ebadi [Sun, 9 Dec 2012 01:36:51 +0000 (20:36 -0500)]
Allow mail routing via smarthost

11 years agorelease debian/4
Clinton Ebadi [Fri, 7 Dec 2012 20:14:47 +0000 (15:14 -0500)]
release

11 years agoFerm.conf syntax fixes
Clinton Ebadi [Fri, 7 Dec 2012 20:14:05 +0000 (15:14 -0500)]
Ferm.conf syntax fixes

11 years agorelease debian/3
Clinton Ebadi [Fri, 7 Dec 2012 20:08:53 +0000 (15:08 -0500)]
release

11 years agoEnable user chains
Clinton Ebadi [Fri, 7 Dec 2012 20:07:59 +0000 (15:07 -0500)]
Enable user chains

11 years agoAllow kadmin debian/2
Clinton Ebadi [Thu, 6 Dec 2012 07:53:48 +0000 (02:53 -0500)]
Allow kadmin

11 years agoRelease debian/1
Clinton Ebadi [Fri, 7 Sep 2012 05:35:20 +0000 (01:35 -0400)]
Release

11 years agoInclude service firewall rules
Clinton Ebadi [Fri, 7 Sep 2012 05:22:51 +0000 (01:22 -0400)]
Include service firewall rules
Instead of a per-machine package, keep the ports with the service for
now. Ideally domtool would handle all of this.

12 years agoBasic restrictive firewall debian/0
Clinton Ebadi [Thu, 29 Mar 2012 06:48:44 +0000 (02:48 -0400)]
Basic restrictive firewall
* Only open ports needed for kerberos, afs, ntp, dns requests, ssh
* Only root can open http connections (for apt)
* Outgoing icmp requests disabled for now -- this was thh default,
  not certain if there are any advantages/disadvantages to this
* Include local in/out ports using local conffiles (for now, fwtool
  will surface properly eventually)