1
|
<?xml version="1.0" encoding="UTF-8" ?>
|
2
|
|
3
|
<firewall name="/usr/share/era/modeles/2zones-amonecole.xml" netbios="1" qos="0" version="2.42">
|
4
|
<zones>
|
5
|
<zone name="exterieur" level="10" ip="%%adresse_ip_eth0" network="%%adresse_network_eth0" netmask="%%adresse_netmask_eth0" interface="%%nom_zone_eth0"/>
|
6
|
<zone name="pedago" level="40" ip="%%adresse_ip_eth1" network="%%adresse_network_eth1" netmask="%%adresse_netmask_eth1" interface="%%nom_zone_eth1"/>
|
7
|
<zone name="bastion" level="100" ip="127.0.0.1" network="0.0.0.0" netmask="255.255.255.255" interface="lo"/>
|
8
|
</zones>
|
9
|
<include>
|
10
|
|
11
|
</include>
|
12
|
<services>
|
13
|
<service name="8500" protocol="tcp" ports="8500" id="11" libelle="service 8500" tcpwrapper=""/>
|
14
|
<service name="agents_zephir" protocol="tcp" ports="8090" id="46" libelle="Acces web aux agents Zéphir" tcpwrapper=""/>
|
15
|
<service name="cntlm" protocol="tcp" ports="%%cntlm_port" id="67" libelle="Proxy Cntlm" tcpwrapper=""/>
|
16
|
<service name="cups" protocol="tcp" ports="631" id="76" libelle="Interface CUPS" tcpwrapper=""/>
|
17
|
<service name="dns-tcp" protocol="tcp" ports="53" id="6" libelle="serveur de noms" tcpwrapper=""/>
|
18
|
<service name="dns-udp" protocol="udp" ports="53" id="7" libelle="serveur de noms" tcpwrapper=""/>
|
19
|
<service name="ead" protocol="tcp" ports="4200" id="36" libelle="ead" tcpwrapper=""/>
|
20
|
<service name="ead-fichier" protocol="tcp" ports="4202" id="84" libelle="ead-fichier" tcpwrapper=""/>
|
21
|
<service name="ead-scribe" protocol="tcp" ports="%%revprox_ead_port" id="73" libelle="port EAD du Scribe avec reverse proxy" tcpwrapper=""/>
|
22
|
<service name="ead-server" protocol="tcp" ports="4201" id="83" libelle="ead-server" tcpwrapper=""/>
|
23
|
<service name="echo-reply" protocol="ICMP" ports="0" id="echo-reply" libelle="règle icmp echo-reply" tcpwrapper=""/>
|
24
|
<service name="echo-request" protocol="ICMP" ports="0" id="echo-request" libelle="règle icmp echo-request" tcpwrapper=""/>
|
25
|
<service name="eole-sso" protocol="tcp" ports="%%eolesso_port" id="45" libelle="Service Eole SSO" tcpwrapper=""/>
|
26
|
<service name="esp" protocol="esp" ports="0" id="51" libelle="protocole pour ipsec" tcpwrapper=""/>
|
27
|
<service name="ftp" protocol="tcp" ports="21" id="78" libelle="transfert de fichiers sur le port 21" tcpwrapper=""/>
|
28
|
<service name="ftp-tcp" protocol="tcp" ports="20-21" id="26" libelle="transfert de fichiers" tcpwrapper=""/>
|
29
|
<service name="ftps" protocol="tcp" ports="989-990" id="29" libelle="service ftps" tcpwrapper=""/>
|
30
|
<service name="gaspacho" protocol="tcp" ports="8080" id="80" libelle="Accès à l'outil Gaspacho" tcpwrapper=""/>
|
31
|
<service name="gen_config" protocol="tcp" ports="7000" id="68" libelle="Accès à gen_config depuis l'extérieur en https" tcpwrapper=""/>
|
32
|
<service name="http" protocol="tcp" ports="80" id="3" libelle="serveur web" tcpwrapper=""/>
|
33
|
<service name="https" protocol="tcp" ports="443" id="5" libelle="serveur web sécurisé" tcpwrapper=""/>
|
34
|
<service name="imap" protocol="tcp" ports="143" id="21" libelle="service imap" tcpwrapper=""/>
|
35
|
<service name="imap4-ssl" protocol="tcp" ports="993" id="23" libelle="service imap4-ssl" tcpwrapper=""/>
|
36
|
<service name="irc" protocol="tcp" ports="194" id="15" libelle="service irc" tcpwrapper=""/>
|
37
|
<service name="ircs" protocol="tcp" ports="994" id="16" libelle="service ircs" tcpwrapper=""/>
|
38
|
<service name="ircu" protocol="tcp" ports="6665-6669" id="13" libelle="service ircu" tcpwrapper=""/>
|
39
|
<service name="isakmp_4500" protocol="udp" ports="4500" id="53" libelle="protocole pour ipsec" tcpwrapper=""/>
|
40
|
<service name="isakmp_500" protocol="udp" ports="500" id="52" libelle="protocol pour ipsec" tcpwrapper=""/>
|
41
|
<service name="ldap" protocol="tcp" ports="389" id="22" libelle="service d'annuaire" tcpwrapper="slapd"/>
|
42
|
<service name="ldaps" protocol="tcp" ports="636" id="24" libelle="service ldaps" tcpwrapper="slapd"/>
|
43
|
<service name="ldm" protocol="tcp" ports="9571" id="81" libelle="Connexion management for LTSP" tcpwrapper=""/>
|
44
|
<service name="lightsquid" protocol="tcp" ports="%%lightsquid_port" id="54" libelle="port d'accès à l'application lightsquid" tcpwrapper=""/>
|
45
|
<service name="lockd" protocol="tcp" ports="4005" id="61" libelle="" tcpwrapper=""/>
|
46
|
<service name="ltspfsd" protocol="tcp" ports="9220" id="72" libelle="ltspfsd" tcpwrapper=""/>
|
47
|
<service name="mdqs" protocol="tcp" ports="666" id="15" libelle="service mdqs" tcpwrapper=""/>
|
48
|
<service name="mountd" protocol="tcp" ports="4003" id="62" libelle="" tcpwrapper=""/>
|
49
|
<service name="msnp" protocol="tcp" ports="1863" id="17" libelle="service msnp" tcpwrapper=""/>
|
50
|
<service name="nbd-client" protocol="tcp" ports="2000" id="71" libelle="nbd-client" tcpwrapper=""/>
|
51
|
<service name="nbd-server" protocol="tcp" ports="10809" id="80" libelle="Server NBD for Eclair" tcpwrapper=""/>
|
52
|
<service name="news" protocol="tcp" ports="2009" id="32" libelle="nouvelles" tcpwrapper=""/>
|
53
|
<service name="nntp" protocol="tcp" ports="119" id="30" libelle="service nntp" tcpwrapper=""/>
|
54
|
<service name="nntps" protocol="tcp" ports="563" id="31" libelle="service nntps" tcpwrapper=""/>
|
55
|
<service name="ntp" protocol="udp" ports="123" id="56" libelle="serveur de temps" tcpwrapper=""/>
|
56
|
<service name="nuauth" protocol="tcp" ports="4129" id="43" libelle="Serveur d'authentification NuFw" tcpwrapper=""/>
|
57
|
<service name="pftp" protocol="tcp" ports="662" id="28" libelle="service pftp" tcpwrapper=""/>
|
58
|
<service name="pop" protocol="tcp" ports="110" id="20" libelle="service pop" tcpwrapper=""/>
|
59
|
<service name="pop3s" protocol="tcp" ports="995" id="25" libelle="service pop3s" tcpwrapper=""/>
|
60
|
<service name="portmap" protocol="tcp" ports="111" id="60" libelle="" tcpwrapper=""/>
|
61
|
<service name="posh-admin" protocol="tcp" ports="7070" id="48" libelle="administration posh" tcpwrapper=""/>
|
62
|
<service name="proxy" protocol="tcp" ports="3128" id="4" libelle="service proxy" tcpwrapper=""/>
|
63
|
<service name="proxy-8080" protocol="tcp" ports="8080" id="12" libelle="proxy" tcpwrapper=""/>
|
64
|
<service name="proxy2" protocol="tcp" ports="%%proxy2_port" id="55" libelle="port 2eme instance de squid" tcpwrapper=""/>
|
65
|
<service name="pulseaudio" protocol="tcp" ports="16001" id="70" libelle="pulseaudio" tcpwrapper=""/>
|
66
|
<service name="radius" protocol="udp" ports="1812" id="70" libelle="" tcpwrapper=""/>
|
67
|
<service name="radius-acct" protocol="udp" ports="1813" id="74" libelle="" tcpwrapper=""/>
|
68
|
<service name="raw" protocol="tcp" ports="9100" id="82" libelle="Service d'impression Raw" tcpwrapper=""/>
|
69
|
<service name="revprox-sso" protocol="tcp" ports="8443" id="79" libelle="Redirection du service EoleSSO" tcpwrapper=""/>
|
70
|
<service name="rsyslog_RELP" protocol="tcp" ports="20514" id="64" libelle="protocole RELP pour rsyslog" tcpwrapper=""/>
|
71
|
<service name="rsyslog_TCP" protocol="tcp" ports="10514" id="65" libelle="protocole TCP pour rsyslog" tcpwrapper=""/>
|
72
|
<service name="rsyslog_UDP" protocol="udp" ports="514" id="66" libelle="protocole UDP pour rsyslog" tcpwrapper=""/>
|
73
|
<service name="samba-tcp" protocol="tcp" ports="137-139" id="38" libelle="samba tcp" tcpwrapper=""/>
|
74
|
<service name="samba-udp" protocol="udp" ports="137-139" id="37" libelle="samba" tcpwrapper=""/>
|
75
|
<service name="samba3" protocol="tcp" ports="445" id="39" libelle="samba3" tcpwrapper=""/>
|
76
|
<service name="scribe-controlevnc" protocol="tcp" ports="8789-8790" id="45" libelle="" tcpwrapper=""/>
|
77
|
<service name="scribe-service" protocol="tcp" ports="8788" id="36" libelle="service scribe sur les clients" tcpwrapper=""/>
|
78
|
<service name="scribe_vnc1" protocol="tcp" ports="5800" id="40" libelle="vnc 5800" tcpwrapper=""/>
|
79
|
<service name="scribe_vnc2" protocol="tcp" ports="5900" id="41" libelle="vnc 5900" tcpwrapper=""/>
|
80
|
<service name="serveur_nfs" protocol="tcp" ports="2049" id="59" libelle="Serveur NFS" tcpwrapper=""/>
|
81
|
<service name="sftp" protocol="tcp" ports="115" id="27" libelle="service sftp" tcpwrapper=""/>
|
82
|
<service name="smtp" protocol="tcp" ports="25" id="19" libelle="service mail" tcpwrapper=""/>
|
83
|
<service name="smtps" protocol="tcp" ports="465" id="77" libelle="Service SMTP SSL" tcpwrapper=""/>
|
84
|
<service name="ssh" protocol="tcp" ports="22" id="8" libelle="shell sécrurisé" tcpwrapper="sshd"/>
|
85
|
<service name="sympa-internet" protocol="tcp" ports="8787" id="58" libelle="serveur sympa internet" tcpwrapper=""/>
|
86
|
<service name="sympa-restreint" protocol="tcp" ports="8888" id="57" libelle="sympa domaine restreint" tcpwrapper=""/>
|
87
|
<service name="talk" protocol="tcp" ports="517-518" id="18" libelle="service talk" tcpwrapper=""/>
|
88
|
<service name="tcp" protocol="tcp" ports="0-65535" id="33" libelle="tous les ports en tcp" tcpwrapper=""/>
|
89
|
<service name="tftpd-hpa" protocol="udp" ports="69" id="75" libelle="Accès aux serveurs TFTP" tcpwrapper="in.tftpd"/>
|
90
|
<service name="tous" protocol="TOUT" ports="0" id="tout" libelle="tous les services" tcpwrapper=""/>
|
91
|
<service name="udp" protocol="udp" ports="0-65535" id="34" libelle="tous les ports en udp" tcpwrapper=""/>
|
92
|
<service name="webmin" protocol="tcp" ports="10000" id="9" libelle="appliquation web d'administration" tcpwrapper=""/>
|
93
|
<service name="xmpp" protocol="tcp" ports="5222" id="63" libelle="Serveur jabber (XMPP)" tcpwrapper=""/>
|
94
|
<service name="xmpp-ssl" protocol="tcp" ports="5223" id="81" libelle="Serveur jabber SSL (XMPP)" tcpwrapper=""/>
|
95
|
<groupe id="admin_amon" libelle="Port autorise pour l'administration distante d'Amon (ssh, ead, agents zephir)">
|
96
|
<service name="agents_zephir" protocol="tcp" ports="8090" id="46" libelle="Acces web aux agents Zéphir" tcpwrapper=""/>
|
97
|
<service name="ead" protocol="tcp" ports="8501" id="10" libelle="Eole Admin" tcpwrapper=""/>
|
98
|
<service name="lightsquid" protocol="tcp" ports="%%lightsquid_port" id="54" libelle="port d'accès à l'application lightsquid" tcpwrapper=""/>
|
99
|
<service name="echo-request" protocol="ICMP" ports="0" id="echo-request" libelle="règle icmp echo-request" tcpwrapper=""/>
|
100
|
</groupe>
|
101
|
<groupe id="amonecole-eclair" libelle="LTSP services">
|
102
|
<service name="ldm" protocol="tcp" ports="9571" id="81" libelle="Connexion management for LTSP" tcpwrapper=""/>
|
103
|
<service name="nbd-server" protocol="tcp" ports="10809" id="80" libelle="Server NBD for Eclair" tcpwrapper=""/>
|
104
|
<service name="ssh" protocol="tcp" ports="22" id="8" libelle="shell sécrurisé" tcpwrapper="sshd"/>
|
105
|
</groupe>
|
106
|
<groupe id="amonecole-eclair-partage" libelle="Services in partage container for Eclair">
|
107
|
<service name="gaspacho" protocol="tcp" ports="8080" id="80" libelle="Accès à l'outil Gaspacho" tcpwrapper=""/>
|
108
|
<service name="tftpd-hpa" protocol="udp" ports="69" id="75" libelle="Accès aux serveurs TFTP" tcpwrapper="in.tftpd"/>
|
109
|
</groupe>
|
110
|
<groupe id="dns" libelle="dns tcp et udp">
|
111
|
<service name="dns-udp" protocol="udp" ports="53" id="7" libelle="serveur de noms" tcpwrapper=""/>
|
112
|
<service name="dns-tcp" protocol="tcp" ports="53" id="6" libelle="serveur de noms" tcpwrapper=""/>
|
113
|
</groupe>
|
114
|
<groupe id="ead_server" libelle="Ports autorises pour l'administration distante d'Amon (backend ead)">
|
115
|
<service name="ead-server" protocol="tcp" ports="4201" id="83" libelle="ead-server" tcpwrapper=""/>
|
116
|
<service name="ead-fichier" protocol="tcp" ports="4202" id="84" libelle="ead-fichier" tcpwrapper=""/>
|
117
|
</groupe>
|
118
|
<groupe id="eclair-dmz" libelle="Eclair en DMZ">
|
119
|
<service name="ltspfsd" protocol="tcp" ports="9220" id="72" libelle="ltspfsd" tcpwrapper=""/>
|
120
|
<service name="nbd-client" protocol="tcp" ports="2000" id="71" libelle="nbd-client" tcpwrapper=""/>
|
121
|
<service name="pulseaudio" protocol="tcp" ports="16001" id="70" libelle="pulseaudio" tcpwrapper=""/>
|
122
|
<service name="scribe_vnc2" protocol="tcp" ports="5900" id="41" libelle="vnc 5900" tcpwrapper=""/>
|
123
|
</groupe>
|
124
|
<groupe id="gr_forum" libelle="interdire l'utilisation des forums">
|
125
|
<service name="nntp" protocol="tcp" ports="119" id="30" libelle="service nntp" tcpwrapper=""/>
|
126
|
<service name="nntps" protocol="tcp" ports="563" id="31" libelle="service nntps" tcpwrapper=""/>
|
127
|
<service name="news" protocol="tcp" ports="2009" id="32" libelle="nouvelles" tcpwrapper=""/>
|
128
|
</groupe>
|
129
|
<groupe id="gr_ftp" libelle="">
|
130
|
<service name="ftp-tcp" protocol="tcp" ports="20-21" id="26" libelle="transfert de fichiers" tcpwrapper=""/>
|
131
|
<service name="ftps" protocol="tcp" ports="989-990" id="29" libelle="service ftps" tcpwrapper=""/>
|
132
|
<service name="pftp" protocol="tcp" ports="662" id="28" libelle="service pftp" tcpwrapper=""/>
|
133
|
<service name="sftp" protocol="tcp" ports="115" id="27" libelle="service sftp" tcpwrapper=""/>
|
134
|
</groupe>
|
135
|
<groupe id="gr_imap" libelle="imap et imap-ssl">
|
136
|
<service name="imap" protocol="tcp" ports="143" id="21" libelle="service imap" tcpwrapper=""/>
|
137
|
<service name="imap4-ssl" protocol="tcp" ports="585" id="23" libelle="service imap4-ssl" tcpwrapper=""/>
|
138
|
</groupe>
|
139
|
<groupe id="gr_irc" libelle="interdire l'utilisation des dialogues en direct (icq)">
|
140
|
<service name="talk" protocol="tcp" ports="517-518" id="18" libelle="service talk" tcpwrapper=""/>
|
141
|
<service name="msnp" protocol="tcp" ports="1863" id="17" libelle="service msnp" tcpwrapper=""/>
|
142
|
<service name="mdqs" protocol="tcp" ports="666" id="15" libelle="service mdqs" tcpwrapper=""/>
|
143
|
<service name="ircs" protocol="tcp" ports="994" id="16" libelle="service ircs" tcpwrapper=""/>
|
144
|
<service name="irc" protocol="tcp" ports="194" id="15" libelle="service irc" tcpwrapper=""/>
|
145
|
<service name="ircu" protocol="tcp" ports="6665-6669" id="13" libelle="service ircu" tcpwrapper=""/>
|
146
|
</groupe>
|
147
|
<groupe id="gr_messagerie" libelle="interdire l'utilisation des dialogues en direct (icq)">
|
148
|
<service name="imap" protocol="tcp" ports="143" id="21" libelle="service imap" tcpwrapper=""/>
|
149
|
<service name="imap4-ssl" protocol="tcp" ports="585" id="23" libelle="service imap4-ssl" tcpwrapper=""/>
|
150
|
<service name="ldap" protocol="tcp" ports="389" id="22" libelle="service d'annuaire" tcpwrapper=""/>
|
151
|
<service name="ldaps" protocol="tcp" ports="636" id="24" libelle="service ldaps" tcpwrapper=""/>
|
152
|
<service name="pop" protocol="tcp" ports="110" id="20" libelle="service pop" tcpwrapper=""/>
|
153
|
<service name="pop3s" protocol="tcp" ports="995" id="25" libelle="service pop3s" tcpwrapper=""/>
|
154
|
<service name="smtp" protocol="tcp" ports="25" id="19" libelle="service mail" tcpwrapper=""/>
|
155
|
<service name="smtps" protocol="tcp" ports="465" id="77" libelle="Service SMTP SSL" tcpwrapper=""/>
|
156
|
</groupe>
|
157
|
<groupe id="gr_pop" libelle="pop3 et pop3s">
|
158
|
<service name="pop" protocol="tcp" ports="110" id="20" libelle="service pop" tcpwrapper=""/>
|
159
|
<service name="pop3s" protocol="tcp" ports="995" id="25" libelle="service pop3s" tcpwrapper=""/>
|
160
|
</groupe>
|
161
|
<groupe id="gr_radius" libelle="Serveur radius (UDP)">
|
162
|
<service name="radius" protocol="udp" ports="1812" id="70" libelle="" tcpwrapper=""/>
|
163
|
<service name="radius-acct" protocol="udp" ports="1813" id="74" libelle="" tcpwrapper=""/>
|
164
|
</groupe>
|
165
|
<groupe id="gr_redirection" libelle="Protocoles a rediriger vers le proxy">
|
166
|
<service name="http" protocol="tcp" ports="80" id="3" libelle="serveur web" tcpwrapper=""/>
|
167
|
<service name="proxy" protocol="tcp" ports="3128" id="4" libelle="service proxy" tcpwrapper=""/>
|
168
|
<service name="proxy-8080" protocol="tcp" ports="8080" id="12" libelle="proxy" tcpwrapper=""/>
|
169
|
<service name="https" protocol="tcp" ports="443" id="5" libelle="web sécurisé" tcpwrapper=""/>
|
170
|
</groupe>
|
171
|
<groupe id="gr_redirection_http" libelle="Protocoles http a rediriger vers le proxy">
|
172
|
<service name="http" protocol="tcp" ports="80" id="3" libelle="serveur web" tcpwrapper=""/>
|
173
|
<service name="proxy" protocol="tcp" ports="3128" id="4" libelle="service proxy" tcpwrapper=""/>
|
174
|
<service name="proxy-8080" protocol="tcp" ports="8080" id="12" libelle="proxy" tcpwrapper=""/>
|
175
|
</groupe>
|
176
|
<groupe id="gr_redirection_https" libelle="Https a redifiger vers le proxy">
|
177
|
<service name="https" protocol="tcp" ports="443" id="5" libelle="web sécurisé" tcpwrapper=""/>
|
178
|
</groupe>
|
179
|
<groupe id="gr_redirection_proxy" libelle="Protocoles proxy a rediriger vers le proxy">
|
180
|
<service name="proxy" protocol="tcp" ports="3128" id="4" libelle="service proxy" tcpwrapper=""/>
|
181
|
<service name="proxy-8080" protocol="tcp" ports="8080" id="12" libelle="proxy" tcpwrapper=""/>
|
182
|
</groupe>
|
183
|
<groupe id="gr_restreint" libelle="on ferme tout sauf l'utilisation du web par le proxy">
|
184
|
<service name="tcp" protocol="tcp" ports="0-65535" id="33" libelle="tous les ports en tcp" tcpwrapper=""/>
|
185
|
<service name="udp" protocol="udp" ports="0-65535" id="34" libelle="tous les ports en udp" tcpwrapper=""/>
|
186
|
</groupe>
|
187
|
<groupe id="gr_smtp" libelle="smtp et smtps">
|
188
|
<service name="smtp" protocol="tcp" ports="25" id="19" libelle="service mail" tcpwrapper=""/>
|
189
|
<service name="smtps" protocol="tcp" ports="465" id="77" libelle="Service SMTP SSL" tcpwrapper=""/>
|
190
|
</groupe>
|
191
|
<groupe id="ipsec" libelle="Services utilises pas ipsec">
|
192
|
<service name="esp" protocol="esp" ports="0" id="51" libelle="protocole pour ipsec" tcpwrapper=""/>
|
193
|
<service name="isakmp_4500" protocol="udp" ports="4500" id="53" libelle="protocole pour ipsec" tcpwrapper=""/>
|
194
|
<service name="isakmp_500" protocol="udp" ports="500" id="52" libelle="protocol pour ipsec" tcpwrapper=""/>
|
195
|
</groupe>
|
196
|
<groupe id="nfs" libelle="Serveur NFS + portmap">
|
197
|
<service name="portmap" protocol="tcp" ports="111" id="60" libelle="" tcpwrapper=""/>
|
198
|
<service name="lockd" protocol="tcp" ports="4005" id="61" libelle="" tcpwrapper=""/>
|
199
|
<service name="mountd" protocol="tcp" ports="4003" id="62" libelle="" tcpwrapper=""/>
|
200
|
<service name="serveur_nfs" protocol="tcp" ports="2049" id="59" libelle="Serveur NFS" tcpwrapper=""/>
|
201
|
</groupe>
|
202
|
<groupe id="samba" libelle="samba proto">
|
203
|
<service name="samba-udp" protocol="udp" ports="137-139" id="37" libelle="samba" tcpwrapper=""/>
|
204
|
<service name="samba-tcp" protocol="tcp" ports="137-139" id="38" libelle="samba tcp" tcpwrapper=""/>
|
205
|
<service name="samba3" protocol="tcp" ports="445" id="39" libelle="samba3" tcpwrapper=""/>
|
206
|
</groupe>
|
207
|
<groupe id="scribe-dmz-pedago" libelle="service Scribe DMZ vers pedago">
|
208
|
<service name="samba-tcp" protocol="tcp" ports="137-139" id="38" libelle="samba tcp" tcpwrapper=""/>
|
209
|
<service name="samba-udp" protocol="udp" ports="137-139" id="37" libelle="samba" tcpwrapper=""/>
|
210
|
<service name="samba3" protocol="tcp" ports="445" id="39" libelle="samba3" tcpwrapper=""/>
|
211
|
<service name="scribe-service" protocol="tcp" ports="8788" id="36" libelle="service scribe sur les clients" tcpwrapper=""/>
|
212
|
<service name="scribe_vnc1" protocol="tcp" ports="5800" id="40" libelle="vnc 5800" tcpwrapper=""/>
|
213
|
<service name="scribe_vnc2" protocol="tcp" ports="5900" id="41" libelle="vnc 5900" tcpwrapper=""/>
|
214
|
<service name="cups" protocol="tcp" ports="631" id="76" libelle="Interface CUPS" tcpwrapper=""/>
|
215
|
<service name="raw" protocol="tcp" ports="9100" id="82" libelle="Service d'impression Raw" tcpwrapper=""/>
|
216
|
</groupe>
|
217
|
<groupe id="scribe-pedago-dmz" libelle="client scribe vers la DMZ">
|
218
|
<service name="ldap" protocol="tcp" ports="389" id="22" libelle="service d'annuaire" tcpwrapper=""/>
|
219
|
<service name="ldaps" protocol="tcp" ports="636" id="24" libelle="service ldaps" tcpwrapper=""/>
|
220
|
<service name="samba-tcp" protocol="tcp" ports="137-139" id="38" libelle="samba tcp" tcpwrapper=""/>
|
221
|
<service name="samba-udp" protocol="udp" ports="137-139" id="37" libelle="samba" tcpwrapper=""/>
|
222
|
<service name="samba3" protocol="tcp" ports="445" id="39" libelle="samba3" tcpwrapper=""/>
|
223
|
<service name="scribe-controlevnc" protocol="tcp" ports="8789-8790" id="45" libelle="" tcpwrapper=""/>
|
224
|
<service name="scribe_vnc1" protocol="tcp" ports="5800" id="40" libelle="vnc 5800" tcpwrapper=""/>
|
225
|
<service name="scribe_vnc2" protocol="tcp" ports="5900" id="41" libelle="vnc 5900" tcpwrapper=""/>
|
226
|
</groupe>
|
227
|
<groupe id="scribe-posh" libelle="Ouverture des ports pour l'utilisation de nginx pour Posh">
|
228
|
<service name="http" protocol="tcp" ports="80" id="3" libelle="serveur web" tcpwrapper=""/>
|
229
|
<service name="https" protocol="tcp" ports="443" id="5" libelle="web sécurisé" tcpwrapper=""/>
|
230
|
<service name="posh-admin" protocol="tcp" ports="7070" id="48" libelle="administration posh" tcpwrapper=""/>
|
231
|
</groupe>
|
232
|
<groupe id="scribe_ext" libelle="services extranet scribe ">
|
233
|
<service name="ftp-tcp" protocol="tcp" ports="20-21" id="26" libelle="transfert de fichiers" tcpwrapper=""/>
|
234
|
<service name="https" protocol="tcp" ports="443" id="5" libelle="web sécurisé" tcpwrapper=""/>
|
235
|
</groupe>
|
236
|
<groupe id="sympa" libelle="serveur sympa">
|
237
|
<service name="sympa-internet" protocol="tcp" ports="8787" id="58" libelle="serveur sympa internet" tcpwrapper=""/>
|
238
|
<service name="sympa-restreint" protocol="tcp" ports="8888" id="57" libelle="sympa domaine restreint" tcpwrapper=""/>
|
239
|
</groupe>
|
240
|
<groupe id="vnc" libelle="vnc">
|
241
|
<service name="scribe_vnc1" protocol="tcp" ports="5800" id="40" libelle="vnc 5800" tcpwrapper=""/>
|
242
|
<service name="scribe_vnc2" protocol="tcp" ports="5900" id="41" libelle="vnc 5900" tcpwrapper=""/>
|
243
|
</groupe>
|
244
|
</services>
|
245
|
<qosclasses upload="" download="">
|
246
|
</qosclasses>
|
247
|
<extremites>
|
248
|
<extremite zone="bastion" name="ltspserver" libelle="LTSP on internal bridge" netmask="255.255.255.255" subnet="0" type="conteneur" interface="containers" container="ltspserver">
|
249
|
<ip address="%%container_ip_ltspserver"/>
|
250
|
</extremite>
|
251
|
<extremite zone="bastion" name="partage" libelle="conteneur partage" netmask="255.255.255.255" subnet="0" type="conteneur" interface="containers" container="partage">
|
252
|
<ip address="%%container_ip_partage"/>
|
253
|
</extremite>
|
254
|
<extremite zone="exterieur" name="pedago_bastion" libelle="" netmask="255.255.255.255" subnet="0" type="" interface="" container="">
|
255
|
<ip address="%%adresse_ip_eth1"/>
|
256
|
</extremite>
|
257
|
<extremite zone="exterieur" name="exterieur" libelle="Zone entière" netmask="%%adresse_netmask_eth0" subnet="1" type="" interface="" container="">
|
258
|
<ip address="%%adresse_ip_eth0"/>
|
259
|
</extremite>
|
260
|
<extremite zone="bastion" name="bdd" libelle="conteneur bdd" netmask="255.255.255.255" subnet="0" type="conteneur" interface="containers" container="bdd">
|
261
|
<ip address="%%container_ip_bdd"/>
|
262
|
</extremite>
|
263
|
<extremite zone="exterieur" name="exterieur_admin" libelle="reseau autorise a administrer depuis l'exterieur" netmask="%%netmask_admin_eth0" subnet="1" type="" interface="" container="">
|
264
|
<ip address="%%ip_admin_eth0"/>
|
265
|
</extremite>
|
266
|
<extremite zone="exterieur" name="exterieur_restreint" libelle="zone restreinte" netmask="%%adresse_netmask_eth0" subnet="1" type="" interface="" container="">
|
267
|
<ip address="%%adresse_network_eth0"/>
|
268
|
</extremite>
|
269
|
<extremite zone="exterieur" name="clients_relp_rsyslog" libelle="clients de l'agrégateur de logs en relp" netmask="%%netmask_client_logs_relp" subnet="0" type="" interface="" container="">
|
270
|
<ip address="%%adresses_ip_clients_logs_relp"/>
|
271
|
</extremite>
|
272
|
<extremite zone="exterieur" name="clients_tcp_rsyslog" libelle="clients de l'agrégateur de logs en tcp" netmask="%%netmask_client_logs_tcp" subnet="0" type="" interface="" container="">
|
273
|
<ip address="%%adresses_ip_clients_logs_tcp"/>
|
274
|
</extremite>
|
275
|
<extremite zone="exterieur" name="clients_udp_rsyslog" libelle="clients de l'agrégateur de logs en udp" netmask="%%netmask_client_logs_udp" subnet="0" type="" interface="" container="">
|
276
|
<ip address="%%adresses_ip_clients_logs_udp"/>
|
277
|
</extremite>
|
278
|
<extremite zone="bastion" name="bastion_exterieur" libelle="Bastion sur la zone exterieur" netmask="255.255.255.255" subnet="0" type="normal" interface="eth0" container="">
|
279
|
<ip address="%%adresse_ip_eth0"/>
|
280
|
</extremite>
|
281
|
<extremite zone="exterieur" name="exterieur_backend_ead" libelle="reseau autorise a acceder au backend EAD depuis l'exterieur" netmask="%%netmask_frontend_ead_distant_eth0" subnet="1" type="" interface="" container="">
|
282
|
<ip address="%%ip_frontend_ead_distant_eth0"/>
|
283
|
</extremite>
|
284
|
<extremite zone="bastion" name="internet_eth1" libelle="eth1 dans le conteneur internet" netmask="255.255.255.255" subnet="0" type="conteneur" interface="eth1" container="internet">
|
285
|
<ip address="%%adresse_ip_eth1_proxy_link"/>
|
286
|
</extremite>
|
287
|
<extremite zone="bastion" name="reseau" libelle="conteneur reseau" netmask="255.255.255.255" subnet="0" type="conteneur" interface="containers" container="reseau">
|
288
|
<ip address="%%container_ip_reseau"/>
|
289
|
</extremite>
|
290
|
<extremite zone="bastion" name="partage_eth1" libelle="eth1 dans le conteneur partage" netmask="255.255.255.255" subnet="0" type="conteneur" interface="eth1" container="partage">
|
291
|
<ip address="%%adresse_ip_fichier_link"/>
|
292
|
</extremite>
|
293
|
<extremite zone="pedago" name="pedago_restreint" libelle="zone restreinte" netmask="%%adresse_netmask_eth1" subnet="1" type="" interface="" container="">
|
294
|
<ip address="%%adresse_network_eth1"/>
|
295
|
</extremite>
|
296
|
<extremite zone="pedago" name="pedago_ssh" libelle="reseau autorise a se connecter a ssh depuis le reseau pedagogique" netmask="%%netmask_ssh_eth1" subnet="1" type="" interface="" container="">
|
297
|
<ip address="%%ip_ssh_eth1"/>
|
298
|
</extremite>
|
299
|
<extremite zone="pedago" name="pedago" libelle="Zone entière" netmask="%%adresse_netmask_eth1" subnet="1" type="" interface="" container="">
|
300
|
<ip address="%%adresse_ip_eth1"/>
|
301
|
</extremite>
|
302
|
<extremite zone="bastion" name="ltspserver_eth0" libelle="LTSP server" netmask="255.255.255.255" subnet="0" type="conteneur" interface="eth0" container="ltspserver">
|
303
|
<ip address="%%adresse_ip_eclair_link"/>
|
304
|
</extremite>
|
305
|
<extremite zone="exterieur" name="exterieur_ssh" libelle="reseau autorise a se connecter a ssh" netmask="%%netmask_ssh_eth0" subnet="1" type="" interface="" container="">
|
306
|
<ip address="%%ip_ssh_eth0"/>
|
307
|
</extremite>
|
308
|
<extremite zone="pedago" name="pedago_backend_ead" libelle="reseau autorise a acceder au backend EAD depuis le reseau pedagogique" netmask="%%netmask_frontend_ead_distant_eth1" subnet="1" type="" interface="" container="">
|
309
|
<ip address="%%ip_frontend_ead_distant_eth1"/>
|
310
|
</extremite>
|
311
|
<extremite zone="bastion" name="bastion" libelle="Zone entière" netmask="255.255.255.255" subnet="1" type="" interface="" container="">
|
312
|
<ip address="127.0.0.1"/>
|
313
|
</extremite>
|
314
|
<extremite zone="bastion" name="internet" libelle="conteneur internet" netmask="255.255.255.255" subnet="0" type="conteneur" interface="containers" container="internet">
|
315
|
<ip address="%%container_ip_internet"/>
|
316
|
</extremite>
|
317
|
<extremite zone="pedago" name="pedago_admin" libelle="reseau autorise a administrer depuis le reseau pedagogique" netmask="%%netmask_admin_eth1" subnet="1" type="" interface="" container="">
|
318
|
<ip address="%%ip_admin_eth1"/>
|
319
|
</extremite>
|
320
|
<extremite zone="exterieur" name="exterieur_bastion" libelle="IP de bastion sur la zone exterieur" netmask="255.255.255.255" subnet="0" type="" interface="" container="">
|
321
|
<ip address="%%adresse_ip_eth0"/>
|
322
|
</extremite>
|
323
|
<extremite zone="pedago" name="client_nfs" libelle="Client NFS" netmask="255.255.255.255" subnet="0" type="normal" interface="" container="">
|
324
|
<ip address="%%adresses_ip_clients_nfs"/>
|
325
|
</extremite>
|
326
|
<extremite zone="bastion" name="partage_eth1_broadcast" libelle="broadcast eth1 dans le conteneur partage" netmask="255.255.255.255" subnet="0" type="conteneur" interface="eth1" container="partage">
|
327
|
<ip address="%%adresse_bcast_eth1_proxy_link"/>
|
328
|
</extremite>
|
329
|
</extremites>
|
330
|
<ranges>
|
331
|
</ranges>
|
332
|
<user_groups>
|
333
|
</user_groups>
|
334
|
<applications>
|
335
|
</applications>
|
336
|
<flux-list>
|
337
|
<flux zoneA="bastion" zoneB="exterieur">
|
338
|
<montantes default_policy="0">
|
339
|
<directive tag="ActiverNGINX" service="scribe-posh" priority="1" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="ouverture de posh a travers de nginx" ipsec="0" accept="0">
|
340
|
<source name="exterieur"/>
|
341
|
<destination name="bastion"/>
|
342
|
</directive>
|
343
|
<directive tag="ead_scribe" service="ead-scribe" priority="2" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="ouverture de l'EAD Scribe a travers de nginx" ipsec="0" accept="0">
|
344
|
<source name="exterieur"/>
|
345
|
<destination name="bastion"/>
|
346
|
</directive>
|
347
|
<directive tag="SSHDepuisEth0" service="ssh" priority="3" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="ssh exterieur vers Amon" ipsec="0" accept="0">
|
348
|
<source name="exterieur_ssh"/>
|
349
|
<destination name="bastion"/>
|
350
|
</directive>
|
351
|
<directive tag="AdminDepuisEth0" service="admin_amon" priority="4" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="administration exterieure vers Amon" ipsec="0" accept="0">
|
352
|
<source name="exterieur_admin"/>
|
353
|
<destination name="bastion"/>
|
354
|
</directive>
|
355
|
<directive tag="BackendEADDepuisEth0" service="ead_server" priority="5" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Acces backend EAD exterieure vers Amon" ipsec="0" accept="0">
|
356
|
<source name="exterieur_backend_ead"/>
|
357
|
<destination name="bastion"/>
|
358
|
</directive>
|
359
|
<directive tag="lightsquid0" service="lightsquid" priority="6" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="administration exterieure vers Amon" ipsec="0" accept="0">
|
360
|
<source name="exterieur_admin"/>
|
361
|
<destination name="bastion"/>
|
362
|
</directive>
|
363
|
<directive tag="eole_sso" service="eole-sso" priority="7" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
364
|
<source name="exterieur"/>
|
365
|
<destination name="bastion"/>
|
366
|
</directive>
|
367
|
<directive tag="revprox_sso" service="revprox-sso" priority="8" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="redirection du service EoleSSO par le proxy inverse" ipsec="0" accept="0">
|
368
|
<source name="exterieur"/>
|
369
|
<destination name="bastion"/>
|
370
|
</directive>
|
371
|
<directive service="ipsec" priority="9" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Autoriser ipsec" ipsec="0" accept="0">
|
372
|
<source name="exterieur"/>
|
373
|
<destination name="bastion"/>
|
374
|
</directive>
|
375
|
<directive tag="SSHDepuisEth0" service="gen_config" priority="10" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="gen_config exterieur vers Amon" ipsec="0" accept="0">
|
376
|
<source name="exterieur_ssh"/>
|
377
|
<destination name="bastion"/>
|
378
|
</directive>
|
379
|
<directive tag="ClientRsyslogRELP" service="rsyslog_RELP" priority="11" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
380
|
<source name="clients_relp_rsyslog"/>
|
381
|
<destination name="bastion"/>
|
382
|
</directive>
|
383
|
<directive tag="ClientRsyslogTCP" service="rsyslog_TCP" priority="12" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
384
|
<source name="clients_tcp_rsyslog"/>
|
385
|
<destination name="bastion"/>
|
386
|
</directive>
|
387
|
<directive tag="ClientRsyslogUDP" service="rsyslog_UDP" priority="13" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
388
|
<source name="clients_udp_rsyslog"/>
|
389
|
<destination name="bastion"/>
|
390
|
</directive>
|
391
|
<directive tag="autoriser la reception des mails depuis exterieur" service="smtp" priority="14" action="2" attrs="1" src_inv="0" dest_inv="0" serv_inv="0" libelle="autoriser la reception des mails depuis exterieur" ipsec="0" accept="0">
|
392
|
<source name="exterieur"/>
|
393
|
<destination name="reseau"/>
|
394
|
</directive>
|
395
|
<directive tag="AdminDepuisEth0" service="sympa-internet" priority="15" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="interface web sympa" ipsec="0" accept="0">
|
396
|
<source name="exterieur_admin"/>
|
397
|
<destination name="reseau"/>
|
398
|
</directive>
|
399
|
</montantes>
|
400
|
<descendantes default_policy="1">
|
401
|
</descendantes>
|
402
|
</flux>
|
403
|
<flux zoneA="exterieur" zoneB="pedago">
|
404
|
<montantes default_policy="0">
|
405
|
</montantes>
|
406
|
<descendantes default_policy="1">
|
407
|
<directive service="tous" priority="1" action="16" attrs="0" nat_extr="exterieur_bastion" nat_port="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
408
|
<source name="pedago_restreint"/>
|
409
|
<destination name="exterieur"/>
|
410
|
</directive>
|
411
|
<directive tag="Interdiction des forums" service="gr_forum" priority="2" action="1" attrs="1" src_inv="0" dest_inv="0" serv_inv="0" libelle="pedago -> exterieur : interdire les protocoles de news, forums ..." ipsec="0" accept="0">
|
412
|
<source name="pedago"/>
|
413
|
<destination name="exterieur"/>
|
414
|
</directive>
|
415
|
<directive tag="Interdire les connexions FTP" service="gr_ftp" priority="3" action="1" attrs="1" src_inv="0" dest_inv="0" serv_inv="0" libelle="Interdire les connexions FTP" ipsec="0" accept="0">
|
416
|
<source name="pedago"/>
|
417
|
<destination name="exterieur"/>
|
418
|
</directive>
|
419
|
<directive tag="Interdire l'utilisation des dialogues en direct" service="gr_irc" priority="4" action="1" attrs="1" src_inv="0" dest_inv="0" serv_inv="0" libelle="pedago -> exterieur : interdire les protocoles de discussion en ligne (irc ...)" ipsec="0" accept="0">
|
420
|
<source name="pedago"/>
|
421
|
<destination name="exterieur"/>
|
422
|
</directive>
|
423
|
<directive tag="Interdiction des protocoles de messagerie" service="gr_messagerie" priority="5" action="1" attrs="1" src_inv="0" dest_inv="0" serv_inv="0" libelle="pedago -> exterieur : interdire les protocoles de messagerie (pop, imap ...)" ipsec="0" accept="0">
|
424
|
<source name="pedago"/>
|
425
|
<destination name="exterieur"/>
|
426
|
</directive>
|
427
|
<directive tag="Internet restreint" service="gr_restreint" priority="6" action="1" attrs="1" src_inv="0" dest_inv="0" serv_inv="0" libelle="pedago -> exterieur : tout interdire (sauf le web via le proxy)" ipsec="0" accept="0">
|
428
|
<source name="pedago"/>
|
429
|
<destination name="exterieur"/>
|
430
|
</directive>
|
431
|
<directive tag="ProxyBypass1" service="gr_redirection_proxy" priority="7" action="4" attrs="17" nat_port="3128" src_inv="0" dest_inv="0" serv_inv="0" libelle="Redirection des flux http avec proxy alternatif" ipsec="0" accept="0">
|
432
|
<source name="pedago"/>
|
433
|
<destination name="exterieur"/>
|
434
|
<exception name="" ip="" eolvar="%%proxy_bypass_src_network_eth1/%%calc_classe(%%proxy_bypass_src_netmask_eth1)" src="1" dest="0"/>
|
435
|
<exception name="" ip="" eolvar="%%proxy_bypass_network_eth1/%%calc_classe(%%proxy_bypass_netmask_eth1)" src="0" dest="1"/>
|
436
|
<exception name="" ip="" eolvar="%%proxy_bypass_domain_eth1" src="0" dest="1"/>
|
437
|
</directive>
|
438
|
<directive tag="ProxyBypass1" service="http" priority="8" action="4" attrs="17" nat_port="81" src_inv="0" dest_inv="1" serv_inv="0" libelle="Redirection des flux http sans proxy" ipsec="0" accept="0">
|
439
|
<source name="pedago"/>
|
440
|
<destination name="exterieur_bastion"/>
|
441
|
<exception name="" ip="" eolvar="%%proxy_bypass_src_network_eth1/%%calc_classe(%%proxy_bypass_src_netmask_eth1)" src="1" dest="0"/>
|
442
|
<exception name="" ip="" eolvar="%%proxy_bypass_network_eth1/%%calc_classe(%%proxy_bypass_netmask_eth1)" src="0" dest="1"/>
|
443
|
<exception name="" ip="" eolvar="%%proxy_bypass_domain_eth1" src="0" dest="1"/>
|
444
|
</directive>
|
445
|
<directive tag="ProxyBypass1" service="gr_redirection_https" priority="9" action="4" attrs="17" nat_port="82" src_inv="0" dest_inv="0" serv_inv="0" libelle="Redirection des flux https sans proxy vers une page d'erreur" ipsec="0" accept="0">
|
446
|
<source name="pedago"/>
|
447
|
<destination name="exterieur"/>
|
448
|
<exception name="" ip="" eolvar="%%proxy_bypass_src_network_eth1/%%calc_classe(%%proxy_bypass_src_netmask_eth1)" src="1" dest="0"/>
|
449
|
<exception name="" ip="" eolvar="%%proxy_bypass_network_eth1/%%calc_classe(%%proxy_bypass_netmask_eth1)" src="0" dest="1"/>
|
450
|
<exception name="" ip="" eolvar="%%proxy_bypass_domain_eth1" src="0" dest="1"/>
|
451
|
</directive>
|
452
|
<directive tag="ForceProxy1" service="gr_redirection_proxy" priority="10" action="4" attrs="17" nat_port="3128" src_inv="0" dest_inv="0" serv_inv="0" libelle="Redirection des flux http avec proxy alternatif" ipsec="0" accept="0">
|
453
|
<source name="pedago"/>
|
454
|
<destination name="exterieur"/>
|
455
|
<exception name="" ip="" eolvar="%%proxy_bypass_src_network_eth1/%%calc_classe(%%proxy_bypass_src_netmask_eth1)" src="1" dest="0"/>
|
456
|
<exception name="" ip="" eolvar="%%proxy_bypass_domain_eth1" src="0" dest="1"/>
|
457
|
</directive>
|
458
|
<directive tag="ForceProxy1" service="http" priority="11" action="4" attrs="17" nat_port="81" src_inv="0" dest_inv="1" serv_inv="0" libelle="Redirection des flux http sans proxy vers une page d'erreur" ipsec="0" accept="0">
|
459
|
<source name="pedago"/>
|
460
|
<destination name="exterieur_bastion"/>
|
461
|
<exception name="" ip="" eolvar="%%proxy_bypass_src_network_eth1/%%calc_classe(%%proxy_bypass_src_netmask_eth1)" src="1" dest="0"/>
|
462
|
<exception name="" ip="" eolvar="%%proxy_bypass_domain_eth1" src="0" dest="1"/>
|
463
|
</directive>
|
464
|
<directive tag="ForceProxy1" service="gr_redirection_https" priority="12" action="4" attrs="17" nat_port="82" src_inv="0" dest_inv="0" serv_inv="0" libelle="Redirection des flux https sans proxy vers une page d'erreur" ipsec="0" accept="0">
|
465
|
<source name="pedago"/>
|
466
|
<destination name="exterieur"/>
|
467
|
<exception name="" ip="" eolvar="%%proxy_bypass_src_network_eth1/%%calc_classe(%%proxy_bypass_src_netmask_eth1)" src="1" dest="0"/>
|
468
|
<exception name="" ip="" eolvar="%%proxy_bypass_domain_eth1" src="0" dest="1"/>
|
469
|
</directive>
|
470
|
</descendantes>
|
471
|
</flux>
|
472
|
<flux zoneA="bastion" zoneB="pedago">
|
473
|
<montantes default_policy="0">
|
474
|
<directive tag="SSHDepuisEth1" service="ssh" priority="1" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="ssh pedago vers Amon" ipsec="0" accept="0">
|
475
|
<source name="pedago_ssh"/>
|
476
|
<destination name="bastion"/>
|
477
|
</directive>
|
478
|
<directive tag="AdminDepuisEth1" service="admin_amon" priority="2" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="administration pedago vers Amon" ipsec="0" accept="0">
|
479
|
<source name="pedago_admin"/>
|
480
|
<destination name="bastion"/>
|
481
|
</directive>
|
482
|
<directive tag="lightsquid1" service="lightsquid" priority="3" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="administration pedago vers Amon" ipsec="0" accept="0">
|
483
|
<source name="pedago_admin"/>
|
484
|
<destination name="bastion"/>
|
485
|
</directive>
|
486
|
<directive service="dns-tcp" priority="4" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
487
|
<source name="pedago"/>
|
488
|
<destination name="internet_eth1"/>
|
489
|
</directive>
|
490
|
<directive service="dns-udp" priority="5" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
491
|
<source name="pedago"/>
|
492
|
<destination name="internet_eth1"/>
|
493
|
</directive>
|
494
|
<directive tag="auth_nufw" service="nuauth" priority="6" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="autoriser l'acces a Nuauth" ipsec="0" accept="0">
|
495
|
<source name="pedago"/>
|
496
|
<destination name="bastion"/>
|
497
|
</directive>
|
498
|
<directive tag="eole_sso" service="eole-sso" priority="7" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
499
|
<source name="pedago"/>
|
500
|
<destination name="bastion"/>
|
501
|
</directive>
|
502
|
<directive service="proxy" priority="8" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
503
|
<source name="pedago"/>
|
504
|
<destination name="internet_eth1"/>
|
505
|
</directive>
|
506
|
<directive tag="Activer squid2" service="proxy2" priority="9" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
507
|
<source name="pedago"/>
|
508
|
<destination name="internet_eth1"/>
|
509
|
</directive>
|
510
|
<directive tag="cntlm" service="cntlm" priority="10" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
511
|
<source name="pedago"/>
|
512
|
<destination name="internet_eth1"/>
|
513
|
</directive>
|
514
|
<directive tag="SSHDepuisEth1" service="gen_config" priority="11" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="gen_config pedago vers Amon" ipsec="0" accept="0">
|
515
|
<source name="pedago_ssh"/>
|
516
|
<destination name="bastion"/>
|
517
|
</directive>
|
518
|
<directive tag="BackendEADDepuisEth1" service="ead_server" priority="12" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Acces backend EAD pedago vers Amon" ipsec="0" accept="0">
|
519
|
<source name="pedago_backend_ead"/>
|
520
|
<destination name="bastion"/>
|
521
|
</directive>
|
522
|
<directive tag="ActiverRadiuseth1" service="gr_radius" priority="13" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="raduis admin vers Amon" ipsec="0" accept="0">
|
523
|
<source name="pedago"/>
|
524
|
<destination name="bastion"/>
|
525
|
</directive>
|
526
|
<directive service="http" priority="14" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Autorisation reverse proxy + WPAD" ipsec="0" accept="0">
|
527
|
<source name="pedago"/>
|
528
|
<destination name="bastion_exterieur"/>
|
529
|
</directive>
|
530
|
<directive tag="activer_ldap" service="ldap" priority="15" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
531
|
<source name="pedago"/>
|
532
|
<destination name="bdd"/>
|
533
|
</directive>
|
534
|
<directive tag="activer_ldaps" service="ldaps" priority="16" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
535
|
<source name="pedago"/>
|
536
|
<destination name="bdd"/>
|
537
|
</directive>
|
538
|
<directive service="ntp" priority="17" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="autoriser les requetes ntp" ipsec="0" accept="0">
|
539
|
<source name="pedago"/>
|
540
|
<destination name="bastion"/>
|
541
|
</directive>
|
542
|
<directive tag="AdminDepuisEth1" service="sympa-internet" priority="18" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="interface web sympa" ipsec="0" accept="0">
|
543
|
<source name="pedago_admin"/>
|
544
|
<destination name="reseau"/>
|
545
|
</directive>
|
546
|
<directive service="sympa-restreint" priority="19" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="interface web sympa" ipsec="0" accept="0">
|
547
|
<source name="pedago"/>
|
548
|
<destination name="reseau"/>
|
549
|
</directive>
|
550
|
<directive tag="activer_nfs" service="nfs" priority="20" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Activer NFS depuis les clients" ipsec="0" accept="0">
|
551
|
<source name="client_nfs"/>
|
552
|
<destination name="bastion"/>
|
553
|
</directive>
|
554
|
<directive tag="activer_courrier_imap" service="imap" priority="21" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
555
|
<source name="pedago"/>
|
556
|
<destination name="reseau"/>
|
557
|
</directive>
|
558
|
<directive tag="activer_courrier_imap" service="imap4-ssl" priority="22" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
559
|
<source name="pedago"/>
|
560
|
<destination name="reseau"/>
|
561
|
</directive>
|
562
|
<directive tag="activer_courrier_pop" service="pop" priority="23" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
563
|
<source name="pedago"/>
|
564
|
<destination name="reseau"/>
|
565
|
</directive>
|
566
|
<directive tag="activer_courrier_pop" service="pop3s" priority="24" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
567
|
<source name="pedago"/>
|
568
|
<destination name="reseau"/>
|
569
|
</directive>
|
570
|
<directive service="smtp" priority="25" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
571
|
<source name="pedago"/>
|
572
|
<destination name="reseau"/>
|
573
|
</directive>
|
574
|
<directive service="smtps" priority="26" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
575
|
<source name="pedago"/>
|
576
|
<destination name="reseau"/>
|
577
|
</directive>
|
578
|
<directive tag="activer_xmpp" service="xmpp" priority="27" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
579
|
<source name="pedago"/>
|
580
|
<destination name="reseau"/>
|
581
|
</directive>
|
582
|
<directive tag="activer_xmpp" service="xmpp-ssl" priority="28" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
583
|
<source name="pedago"/>
|
584
|
<destination name="reseau"/>
|
585
|
</directive>
|
586
|
<directive tag="activer_tftp" service="tftpd-hpa" priority="29" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
|
587
|
<source name="pedago"/>
|
588
|
<destination name="bdd"/>
|
589
|
</directive>
|
590
|
<directive tag="activer_cups1" service="cups" priority="30" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="interface web CUPS" ipsec="0" accept="0">
|
591
|
<source name="pedago_admin"/>
|
592
|
<destination name="partage_eth1"/>
|
593
|
</directive>
|
594
|
<directive service="scribe-controlevnc" priority="31" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Controle VNC" ipsec="0" accept="0">
|
595
|
<source name="pedago"/>
|
596
|
<destination name="partage_eth1"/>
|
597
|
</directive>
|
598
|
<directive tag="activer_proftpd" service="ftp" priority="32" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Controle VNC" ipsec="0" accept="0">
|
599
|
<source name="pedago"/>
|
600
|
<destination name="partage_eth1"/>
|
601
|
</directive>
|
602
|
<directive service="samba" priority="33" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Controle VNC" ipsec="0" accept="0">
|
603
|
<source name="pedago"/>
|
604
|
<destination name="partage_eth1"/>
|
605
|
</directive>
|
606
|
<directive service="samba" priority="34" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Controle VNC" ipsec="0" accept="0">
|
607
|
<source name="pedago"/>
|
608
|
<destination name="partage_eth1_broadcast"/>
|
609
|
</directive>
|
610
|
<directive service="echo-request" priority="35" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Autorise le ping vers le conteneur" ipsec="0" accept="0">
|
611
|
<source name="pedago"/>
|
612
|
<destination name="partage_eth1"/>
|
613
|
</directive>
|
614
|
<directive service="echo-request" priority="36" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Autorise le ping vers le conteneur" ipsec="0" accept="0">
|
615
|
<source name="pedago"/>
|
616
|
<destination name="internet_eth1"/>
|
617
|
</directive>
|
618
|
<directive tag="GaspachoEth1" service="gaspacho" priority="37" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Autoriser l'accès à Gaspacho" ipsec="0" accept="0">
|
619
|
<source name="pedago"/>
|
620
|
<destination name="partage_eth1"/>
|
621
|
</directive>
|
622
|
<directive tag="activer_eclair_amonecole" service="amonecole-eclair" priority="38" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Open Eclair ports on AmonEcole" ipsec="0" accept="0">
|
623
|
<source name="pedago"/>
|
624
|
<destination name="ltspserver_eth0"/>
|
625
|
</directive>
|
626
|
<directive tag="activer_eclair_amonecole" service="amonecole-eclair-partage" priority="39" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Open Gaspacho and TFTPD for Eclair on AmonEcole" ipsec="0" accept="0">
|
627
|
<source name="pedago"/>
|
628
|
<destination name="partage_eth1"/>
|
629
|
</directive>
|
630
|
</montantes>
|
631
|
<descendantes default_policy="1">
|
632
|
</descendantes>
|
633
|
</flux>
|
634
|
</flux-list>
|
635
|
</firewall>
|