Projet

Général

Profil

2zones-amonecole.xml

Daniel Dehennin, 22/09/2017 17:40

Télécharger (53,1 ko)

 
1
<?xml version="1.0" encoding="UTF-8" ?>
2

    
3
<firewall name="/usr/share/era/modeles/2zones-amonecole.xml" netbios="1" qos="0" version="2.42">
4
    <zones>
5
        <zone name="exterieur" level="10" ip="%%adresse_ip_eth0" network="%%adresse_network_eth0" netmask="%%adresse_netmask_eth0" interface="%%nom_zone_eth0"/>
6
        <zone name="pedago" level="40" ip="%%adresse_ip_eth1" network="%%adresse_network_eth1" netmask="%%adresse_netmask_eth1" interface="%%nom_zone_eth1"/>
7
        <zone name="bastion" level="100" ip="127.0.0.1" network="0.0.0.0" netmask="255.255.255.255" interface="lo"/>
8
    </zones>
9
    <include>
10

    
11
    </include>
12
    <services>
13
        <service name="8500" protocol="tcp" ports="8500" id="11" libelle="service 8500" tcpwrapper=""/>
14
        <service name="agents_zephir" protocol="tcp" ports="8090" id="46" libelle="Acces web aux agents Zéphir" tcpwrapper=""/>
15
        <service name="cntlm" protocol="tcp" ports="%%cntlm_port" id="67" libelle="Proxy Cntlm" tcpwrapper=""/>
16
        <service name="cups" protocol="tcp" ports="631" id="76" libelle="Interface CUPS" tcpwrapper=""/>
17
        <service name="dns-tcp" protocol="tcp" ports="53" id="6" libelle="serveur de noms" tcpwrapper=""/>
18
        <service name="dns-udp" protocol="udp" ports="53" id="7" libelle="serveur de noms" tcpwrapper=""/>
19
        <service name="ead" protocol="tcp" ports="4200" id="36" libelle="ead" tcpwrapper=""/>
20
        <service name="ead-fichier" protocol="tcp" ports="4202" id="84" libelle="ead-fichier" tcpwrapper=""/>
21
        <service name="ead-scribe" protocol="tcp" ports="%%revprox_ead_port" id="73" libelle="port EAD du Scribe avec reverse proxy" tcpwrapper=""/>
22
        <service name="ead-server" protocol="tcp" ports="4201" id="83" libelle="ead-server" tcpwrapper=""/>
23
        <service name="echo-reply" protocol="ICMP" ports="0" id="echo-reply" libelle="règle icmp echo-reply" tcpwrapper=""/>
24
        <service name="echo-request" protocol="ICMP" ports="0" id="echo-request" libelle="règle icmp echo-request" tcpwrapper=""/>
25
        <service name="eole-sso" protocol="tcp" ports="%%eolesso_port" id="45" libelle="Service Eole SSO" tcpwrapper=""/>
26
        <service name="esp" protocol="esp" ports="0" id="51" libelle="protocole pour ipsec" tcpwrapper=""/>
27
        <service name="ftp" protocol="tcp" ports="21" id="78" libelle="transfert de fichiers sur le port 21" tcpwrapper=""/>
28
        <service name="ftp-tcp" protocol="tcp" ports="20-21" id="26" libelle="transfert de fichiers" tcpwrapper=""/>
29
        <service name="ftps" protocol="tcp" ports="989-990" id="29" libelle="service ftps" tcpwrapper=""/>
30
        <service name="gaspacho" protocol="tcp" ports="8080" id="80" libelle="Accès à l'outil Gaspacho" tcpwrapper=""/>
31
        <service name="gen_config" protocol="tcp" ports="7000" id="68" libelle="Accès à gen_config depuis l'extérieur en https" tcpwrapper=""/>
32
        <service name="http" protocol="tcp" ports="80" id="3" libelle="serveur web" tcpwrapper=""/>
33
        <service name="https" protocol="tcp" ports="443" id="5" libelle="serveur web sécurisé" tcpwrapper=""/>
34
        <service name="imap" protocol="tcp" ports="143" id="21" libelle="service imap" tcpwrapper=""/>
35
        <service name="imap4-ssl" protocol="tcp" ports="993" id="23" libelle="service imap4-ssl" tcpwrapper=""/>
36
        <service name="irc" protocol="tcp" ports="194" id="15" libelle="service irc" tcpwrapper=""/>
37
        <service name="ircs" protocol="tcp" ports="994" id="16" libelle="service ircs" tcpwrapper=""/>
38
        <service name="ircu" protocol="tcp" ports="6665-6669" id="13" libelle="service ircu" tcpwrapper=""/>
39
        <service name="isakmp_4500" protocol="udp" ports="4500" id="53" libelle="protocole pour ipsec" tcpwrapper=""/>
40
        <service name="isakmp_500" protocol="udp" ports="500" id="52" libelle="protocol pour ipsec" tcpwrapper=""/>
41
        <service name="ldap" protocol="tcp" ports="389" id="22" libelle="service d'annuaire" tcpwrapper="slapd"/>
42
        <service name="ldaps" protocol="tcp" ports="636" id="24" libelle="service ldaps" tcpwrapper="slapd"/>
43
        <service name="ldm" protocol="tcp" ports="9571" id="81" libelle="Connexion management for LTSP" tcpwrapper=""/>
44
        <service name="lightsquid" protocol="tcp" ports="%%lightsquid_port" id="54" libelle="port d'accès à l'application lightsquid" tcpwrapper=""/>
45
        <service name="lockd" protocol="tcp" ports="4005" id="61" libelle="" tcpwrapper=""/>
46
        <service name="ltspfsd" protocol="tcp" ports="9220" id="72" libelle="ltspfsd" tcpwrapper=""/>
47
        <service name="mdqs" protocol="tcp" ports="666" id="15" libelle="service mdqs" tcpwrapper=""/>
48
        <service name="mountd" protocol="tcp" ports="4003" id="62" libelle="" tcpwrapper=""/>
49
        <service name="msnp" protocol="tcp" ports="1863" id="17" libelle="service msnp" tcpwrapper=""/>
50
        <service name="nbd-client" protocol="tcp" ports="2000" id="71" libelle="nbd-client" tcpwrapper=""/>
51
        <service name="nbd-server" protocol="tcp" ports="10809" id="80" libelle="Server NBD for Eclair" tcpwrapper=""/>
52
        <service name="news" protocol="tcp" ports="2009" id="32" libelle="nouvelles" tcpwrapper=""/>
53
        <service name="nntp" protocol="tcp" ports="119" id="30" libelle="service nntp" tcpwrapper=""/>
54
        <service name="nntps" protocol="tcp" ports="563" id="31" libelle="service nntps" tcpwrapper=""/>
55
        <service name="ntp" protocol="udp" ports="123" id="56" libelle="serveur de temps" tcpwrapper=""/>
56
        <service name="nuauth" protocol="tcp" ports="4129" id="43" libelle="Serveur d'authentification NuFw" tcpwrapper=""/>
57
        <service name="pftp" protocol="tcp" ports="662" id="28" libelle="service pftp" tcpwrapper=""/>
58
        <service name="pop" protocol="tcp" ports="110" id="20" libelle="service pop" tcpwrapper=""/>
59
        <service name="pop3s" protocol="tcp" ports="995" id="25" libelle="service pop3s" tcpwrapper=""/>
60
        <service name="portmap" protocol="tcp" ports="111" id="60" libelle="" tcpwrapper=""/>
61
        <service name="posh-admin" protocol="tcp" ports="7070" id="48" libelle="administration posh" tcpwrapper=""/>
62
        <service name="proxy" protocol="tcp" ports="3128" id="4" libelle="service proxy" tcpwrapper=""/>
63
        <service name="proxy-8080" protocol="tcp" ports="8080" id="12" libelle="proxy" tcpwrapper=""/>
64
        <service name="proxy2" protocol="tcp" ports="%%proxy2_port" id="55" libelle="port 2eme instance de squid" tcpwrapper=""/>
65
        <service name="pulseaudio" protocol="tcp" ports="16001" id="70" libelle="pulseaudio" tcpwrapper=""/>
66
        <service name="radius" protocol="udp" ports="1812" id="70" libelle="" tcpwrapper=""/>
67
        <service name="radius-acct" protocol="udp" ports="1813" id="74" libelle="" tcpwrapper=""/>
68
        <service name="raw" protocol="tcp" ports="9100" id="82" libelle="Service d'impression Raw" tcpwrapper=""/>
69
        <service name="revprox-sso" protocol="tcp" ports="8443" id="79" libelle="Redirection du service EoleSSO" tcpwrapper=""/>
70
        <service name="rsyslog_RELP" protocol="tcp" ports="20514" id="64" libelle="protocole RELP pour rsyslog" tcpwrapper=""/>
71
        <service name="rsyslog_TCP" protocol="tcp" ports="10514" id="65" libelle="protocole TCP pour rsyslog" tcpwrapper=""/>
72
        <service name="rsyslog_UDP" protocol="udp" ports="514" id="66" libelle="protocole UDP pour rsyslog" tcpwrapper=""/>
73
        <service name="samba-tcp" protocol="tcp" ports="137-139" id="38" libelle="samba tcp" tcpwrapper=""/>
74
        <service name="samba-udp" protocol="udp" ports="137-139" id="37" libelle="samba" tcpwrapper=""/>
75
        <service name="samba3" protocol="tcp" ports="445" id="39" libelle="samba3" tcpwrapper=""/>
76
        <service name="scribe-controlevnc" protocol="tcp" ports="8789-8790" id="45" libelle="" tcpwrapper=""/>
77
        <service name="scribe-service" protocol="tcp" ports="8788" id="36" libelle="service scribe sur les clients" tcpwrapper=""/>
78
        <service name="scribe_vnc1" protocol="tcp" ports="5800" id="40" libelle="vnc 5800" tcpwrapper=""/>
79
        <service name="scribe_vnc2" protocol="tcp" ports="5900" id="41" libelle="vnc 5900" tcpwrapper=""/>
80
        <service name="serveur_nfs" protocol="tcp" ports="2049" id="59" libelle="Serveur NFS" tcpwrapper=""/>
81
        <service name="sftp" protocol="tcp" ports="115" id="27" libelle="service sftp" tcpwrapper=""/>
82
        <service name="smtp" protocol="tcp" ports="25" id="19" libelle="service mail" tcpwrapper=""/>
83
        <service name="smtps" protocol="tcp" ports="465" id="77" libelle="Service SMTP SSL" tcpwrapper=""/>
84
        <service name="ssh" protocol="tcp" ports="22" id="8" libelle="shell sécrurisé" tcpwrapper="sshd"/>
85
        <service name="sympa-internet" protocol="tcp" ports="8787" id="58" libelle="serveur sympa internet" tcpwrapper=""/>
86
        <service name="sympa-restreint" protocol="tcp" ports="8888" id="57" libelle="sympa domaine restreint" tcpwrapper=""/>
87
        <service name="talk" protocol="tcp" ports="517-518" id="18" libelle="service talk" tcpwrapper=""/>
88
        <service name="tcp" protocol="tcp" ports="0-65535" id="33" libelle="tous les ports en tcp" tcpwrapper=""/>
89
        <service name="tftpd-hpa" protocol="udp" ports="69" id="75" libelle="Accès aux serveurs TFTP" tcpwrapper="in.tftpd"/>
90
        <service name="tous" protocol="TOUT" ports="0" id="tout" libelle="tous les services" tcpwrapper=""/>
91
        <service name="udp" protocol="udp" ports="0-65535" id="34" libelle="tous les ports en udp" tcpwrapper=""/>
92
        <service name="webmin" protocol="tcp" ports="10000" id="9" libelle="appliquation web d'administration" tcpwrapper=""/>
93
        <service name="xmpp" protocol="tcp" ports="5222" id="63" libelle="Serveur jabber (XMPP)" tcpwrapper=""/>
94
        <service name="xmpp-ssl" protocol="tcp" ports="5223" id="81" libelle="Serveur jabber SSL (XMPP)" tcpwrapper=""/>
95
        <groupe id="admin_amon" libelle="Port autorise pour l'administration distante d'Amon (ssh, ead, agents zephir)">
96
            <service name="agents_zephir" protocol="tcp" ports="8090" id="46" libelle="Acces web aux agents Zéphir" tcpwrapper=""/>
97
            <service name="ead" protocol="tcp" ports="8501" id="10" libelle="Eole Admin" tcpwrapper=""/>
98
            <service name="lightsquid" protocol="tcp" ports="%%lightsquid_port" id="54" libelle="port d'accès à l'application lightsquid" tcpwrapper=""/>
99
            <service name="echo-request" protocol="ICMP" ports="0" id="echo-request" libelle="règle icmp echo-request" tcpwrapper=""/>
100
        </groupe>
101
        <groupe id="amonecole-eclair" libelle="LTSP services">
102
            <service name="ldm" protocol="tcp" ports="9571" id="81" libelle="Connexion management for LTSP" tcpwrapper=""/>
103
            <service name="nbd-server" protocol="tcp" ports="10809" id="80" libelle="Server NBD for Eclair" tcpwrapper=""/>
104
            <service name="ssh" protocol="tcp" ports="22" id="8" libelle="shell sécrurisé" tcpwrapper="sshd"/>
105
        </groupe>
106
        <groupe id="amonecole-eclair-partage" libelle="Services in partage container for Eclair">
107
            <service name="gaspacho" protocol="tcp" ports="8080" id="80" libelle="Accès à l'outil Gaspacho" tcpwrapper=""/>
108
            <service name="tftpd-hpa" protocol="udp" ports="69" id="75" libelle="Accès aux serveurs TFTP" tcpwrapper="in.tftpd"/>
109
        </groupe>
110
        <groupe id="dns" libelle="dns tcp et udp">
111
            <service name="dns-udp" protocol="udp" ports="53" id="7" libelle="serveur de noms" tcpwrapper=""/>
112
            <service name="dns-tcp" protocol="tcp" ports="53" id="6" libelle="serveur de noms" tcpwrapper=""/>
113
        </groupe>
114
        <groupe id="ead_server" libelle="Ports autorises pour l'administration distante d'Amon (backend ead)">
115
            <service name="ead-server" protocol="tcp" ports="4201" id="83" libelle="ead-server" tcpwrapper=""/>
116
            <service name="ead-fichier" protocol="tcp" ports="4202" id="84" libelle="ead-fichier" tcpwrapper=""/>
117
        </groupe>
118
        <groupe id="eclair-dmz" libelle="Eclair en DMZ">
119
            <service name="ltspfsd" protocol="tcp" ports="9220" id="72" libelle="ltspfsd" tcpwrapper=""/>
120
            <service name="nbd-client" protocol="tcp" ports="2000" id="71" libelle="nbd-client" tcpwrapper=""/>
121
            <service name="pulseaudio" protocol="tcp" ports="16001" id="70" libelle="pulseaudio" tcpwrapper=""/>
122
            <service name="scribe_vnc2" protocol="tcp" ports="5900" id="41" libelle="vnc 5900" tcpwrapper=""/>
123
        </groupe>
124
        <groupe id="gr_forum" libelle="interdire l'utilisation des forums">
125
            <service name="nntp" protocol="tcp" ports="119" id="30" libelle="service nntp" tcpwrapper=""/>
126
            <service name="nntps" protocol="tcp" ports="563" id="31" libelle="service nntps" tcpwrapper=""/>
127
            <service name="news" protocol="tcp" ports="2009" id="32" libelle="nouvelles" tcpwrapper=""/>
128
        </groupe>
129
        <groupe id="gr_ftp" libelle="">
130
            <service name="ftp-tcp" protocol="tcp" ports="20-21" id="26" libelle="transfert de fichiers" tcpwrapper=""/>
131
            <service name="ftps" protocol="tcp" ports="989-990" id="29" libelle="service ftps" tcpwrapper=""/>
132
            <service name="pftp" protocol="tcp" ports="662" id="28" libelle="service pftp" tcpwrapper=""/>
133
            <service name="sftp" protocol="tcp" ports="115" id="27" libelle="service sftp" tcpwrapper=""/>
134
        </groupe>
135
        <groupe id="gr_imap" libelle="imap et imap-ssl">
136
            <service name="imap" protocol="tcp" ports="143" id="21" libelle="service imap" tcpwrapper=""/>
137
            <service name="imap4-ssl" protocol="tcp" ports="585" id="23" libelle="service imap4-ssl" tcpwrapper=""/>
138
        </groupe>
139
        <groupe id="gr_irc" libelle="interdire l'utilisation des dialogues en direct (icq)">
140
            <service name="talk" protocol="tcp" ports="517-518" id="18" libelle="service talk" tcpwrapper=""/>
141
            <service name="msnp" protocol="tcp" ports="1863" id="17" libelle="service msnp" tcpwrapper=""/>
142
            <service name="mdqs" protocol="tcp" ports="666" id="15" libelle="service mdqs" tcpwrapper=""/>
143
            <service name="ircs" protocol="tcp" ports="994" id="16" libelle="service ircs" tcpwrapper=""/>
144
            <service name="irc" protocol="tcp" ports="194" id="15" libelle="service irc" tcpwrapper=""/>
145
            <service name="ircu" protocol="tcp" ports="6665-6669" id="13" libelle="service ircu" tcpwrapper=""/>
146
        </groupe>
147
        <groupe id="gr_messagerie" libelle="interdire l'utilisation des dialogues en direct (icq)">
148
            <service name="imap" protocol="tcp" ports="143" id="21" libelle="service imap" tcpwrapper=""/>
149
            <service name="imap4-ssl" protocol="tcp" ports="585" id="23" libelle="service imap4-ssl" tcpwrapper=""/>
150
            <service name="ldap" protocol="tcp" ports="389" id="22" libelle="service d'annuaire" tcpwrapper=""/>
151
            <service name="ldaps" protocol="tcp" ports="636" id="24" libelle="service ldaps" tcpwrapper=""/>
152
            <service name="pop" protocol="tcp" ports="110" id="20" libelle="service pop" tcpwrapper=""/>
153
            <service name="pop3s" protocol="tcp" ports="995" id="25" libelle="service pop3s" tcpwrapper=""/>
154
            <service name="smtp" protocol="tcp" ports="25" id="19" libelle="service mail" tcpwrapper=""/>
155
            <service name="smtps" protocol="tcp" ports="465" id="77" libelle="Service SMTP SSL" tcpwrapper=""/>
156
        </groupe>
157
        <groupe id="gr_pop" libelle="pop3 et pop3s">
158
            <service name="pop" protocol="tcp" ports="110" id="20" libelle="service pop" tcpwrapper=""/>
159
            <service name="pop3s" protocol="tcp" ports="995" id="25" libelle="service pop3s" tcpwrapper=""/>
160
        </groupe>
161
        <groupe id="gr_radius" libelle="Serveur radius (UDP)">
162
            <service name="radius" protocol="udp" ports="1812" id="70" libelle="" tcpwrapper=""/>
163
            <service name="radius-acct" protocol="udp" ports="1813" id="74" libelle="" tcpwrapper=""/>
164
        </groupe>
165
        <groupe id="gr_redirection" libelle="Protocoles a rediriger vers le proxy">
166
            <service name="http" protocol="tcp" ports="80" id="3" libelle="serveur web" tcpwrapper=""/>
167
            <service name="proxy" protocol="tcp" ports="3128" id="4" libelle="service proxy" tcpwrapper=""/>
168
            <service name="proxy-8080" protocol="tcp" ports="8080" id="12" libelle="proxy" tcpwrapper=""/>
169
            <service name="https" protocol="tcp" ports="443" id="5" libelle="web sécurisé" tcpwrapper=""/>
170
        </groupe>
171
        <groupe id="gr_redirection_http" libelle="Protocoles http a rediriger vers le proxy">
172
            <service name="http" protocol="tcp" ports="80" id="3" libelle="serveur web" tcpwrapper=""/>
173
            <service name="proxy" protocol="tcp" ports="3128" id="4" libelle="service proxy" tcpwrapper=""/>
174
            <service name="proxy-8080" protocol="tcp" ports="8080" id="12" libelle="proxy" tcpwrapper=""/>
175
        </groupe>
176
        <groupe id="gr_redirection_https" libelle="Https a redifiger vers le proxy">
177
            <service name="https" protocol="tcp" ports="443" id="5" libelle="web sécurisé" tcpwrapper=""/>
178
        </groupe>
179
        <groupe id="gr_redirection_proxy" libelle="Protocoles proxy a rediriger vers le proxy">
180
            <service name="proxy" protocol="tcp" ports="3128" id="4" libelle="service proxy" tcpwrapper=""/>
181
            <service name="proxy-8080" protocol="tcp" ports="8080" id="12" libelle="proxy" tcpwrapper=""/>
182
        </groupe>
183
        <groupe id="gr_restreint" libelle="on ferme tout sauf l'utilisation du web par le proxy">
184
            <service name="tcp" protocol="tcp" ports="0-65535" id="33" libelle="tous les ports en tcp" tcpwrapper=""/>
185
            <service name="udp" protocol="udp" ports="0-65535" id="34" libelle="tous les ports en udp" tcpwrapper=""/>
186
        </groupe>
187
        <groupe id="gr_smtp" libelle="smtp et smtps">
188
            <service name="smtp" protocol="tcp" ports="25" id="19" libelle="service mail" tcpwrapper=""/>
189
            <service name="smtps" protocol="tcp" ports="465" id="77" libelle="Service SMTP SSL" tcpwrapper=""/>
190
        </groupe>
191
        <groupe id="ipsec" libelle="Services utilises pas ipsec">
192
            <service name="esp" protocol="esp" ports="0" id="51" libelle="protocole pour ipsec" tcpwrapper=""/>
193
            <service name="isakmp_4500" protocol="udp" ports="4500" id="53" libelle="protocole pour ipsec" tcpwrapper=""/>
194
            <service name="isakmp_500" protocol="udp" ports="500" id="52" libelle="protocol pour ipsec" tcpwrapper=""/>
195
        </groupe>
196
        <groupe id="nfs" libelle="Serveur NFS + portmap">
197
            <service name="portmap" protocol="tcp" ports="111" id="60" libelle="" tcpwrapper=""/>
198
            <service name="lockd" protocol="tcp" ports="4005" id="61" libelle="" tcpwrapper=""/>
199
            <service name="mountd" protocol="tcp" ports="4003" id="62" libelle="" tcpwrapper=""/>
200
            <service name="serveur_nfs" protocol="tcp" ports="2049" id="59" libelle="Serveur NFS" tcpwrapper=""/>
201
        </groupe>
202
        <groupe id="samba" libelle="samba proto">
203
            <service name="samba-udp" protocol="udp" ports="137-139" id="37" libelle="samba" tcpwrapper=""/>
204
            <service name="samba-tcp" protocol="tcp" ports="137-139" id="38" libelle="samba tcp" tcpwrapper=""/>
205
            <service name="samba3" protocol="tcp" ports="445" id="39" libelle="samba3" tcpwrapper=""/>
206
        </groupe>
207
        <groupe id="scribe-dmz-pedago" libelle="service Scribe DMZ vers pedago">
208
            <service name="samba-tcp" protocol="tcp" ports="137-139" id="38" libelle="samba tcp" tcpwrapper=""/>
209
            <service name="samba-udp" protocol="udp" ports="137-139" id="37" libelle="samba" tcpwrapper=""/>
210
            <service name="samba3" protocol="tcp" ports="445" id="39" libelle="samba3" tcpwrapper=""/>
211
            <service name="scribe-service" protocol="tcp" ports="8788" id="36" libelle="service scribe sur les clients" tcpwrapper=""/>
212
            <service name="scribe_vnc1" protocol="tcp" ports="5800" id="40" libelle="vnc 5800" tcpwrapper=""/>
213
            <service name="scribe_vnc2" protocol="tcp" ports="5900" id="41" libelle="vnc 5900" tcpwrapper=""/>
214
            <service name="cups" protocol="tcp" ports="631" id="76" libelle="Interface CUPS" tcpwrapper=""/>
215
            <service name="raw" protocol="tcp" ports="9100" id="82" libelle="Service d'impression Raw" tcpwrapper=""/>
216
        </groupe>
217
        <groupe id="scribe-pedago-dmz" libelle="client scribe vers la DMZ">
218
            <service name="ldap" protocol="tcp" ports="389" id="22" libelle="service d'annuaire" tcpwrapper=""/>
219
            <service name="ldaps" protocol="tcp" ports="636" id="24" libelle="service ldaps" tcpwrapper=""/>
220
            <service name="samba-tcp" protocol="tcp" ports="137-139" id="38" libelle="samba tcp" tcpwrapper=""/>
221
            <service name="samba-udp" protocol="udp" ports="137-139" id="37" libelle="samba" tcpwrapper=""/>
222
            <service name="samba3" protocol="tcp" ports="445" id="39" libelle="samba3" tcpwrapper=""/>
223
            <service name="scribe-controlevnc" protocol="tcp" ports="8789-8790" id="45" libelle="" tcpwrapper=""/>
224
            <service name="scribe_vnc1" protocol="tcp" ports="5800" id="40" libelle="vnc 5800" tcpwrapper=""/>
225
            <service name="scribe_vnc2" protocol="tcp" ports="5900" id="41" libelle="vnc 5900" tcpwrapper=""/>
226
        </groupe>
227
        <groupe id="scribe-posh" libelle="Ouverture des ports pour l'utilisation de nginx pour Posh">
228
            <service name="http" protocol="tcp" ports="80" id="3" libelle="serveur web" tcpwrapper=""/>
229
            <service name="https" protocol="tcp" ports="443" id="5" libelle="web sécurisé" tcpwrapper=""/>
230
            <service name="posh-admin" protocol="tcp" ports="7070" id="48" libelle="administration posh" tcpwrapper=""/>
231
        </groupe>
232
        <groupe id="scribe_ext" libelle="services extranet scribe ">
233
            <service name="ftp-tcp" protocol="tcp" ports="20-21" id="26" libelle="transfert de fichiers" tcpwrapper=""/>
234
            <service name="https" protocol="tcp" ports="443" id="5" libelle="web sécurisé" tcpwrapper=""/>
235
        </groupe>
236
        <groupe id="sympa" libelle="serveur sympa">
237
            <service name="sympa-internet" protocol="tcp" ports="8787" id="58" libelle="serveur sympa internet" tcpwrapper=""/>
238
            <service name="sympa-restreint" protocol="tcp" ports="8888" id="57" libelle="sympa domaine restreint" tcpwrapper=""/>
239
        </groupe>
240
        <groupe id="vnc" libelle="vnc">
241
            <service name="scribe_vnc1" protocol="tcp" ports="5800" id="40" libelle="vnc 5800" tcpwrapper=""/>
242
            <service name="scribe_vnc2" protocol="tcp" ports="5900" id="41" libelle="vnc 5900" tcpwrapper=""/>
243
        </groupe>
244
    </services>
245
    <qosclasses upload="" download="">
246
    </qosclasses>
247
    <extremites>
248
        <extremite zone="bastion" name="ltspserver" libelle="LTSP on internal bridge" netmask="255.255.255.255" subnet="0" type="conteneur" interface="containers" container="ltspserver">
249
            <ip address="%%container_ip_ltspserver"/>
250
        </extremite>
251
        <extremite zone="bastion" name="partage" libelle="conteneur partage" netmask="255.255.255.255" subnet="0" type="conteneur" interface="containers" container="partage">
252
            <ip address="%%container_ip_partage"/>
253
        </extremite>
254
        <extremite zone="exterieur" name="pedago_bastion" libelle="" netmask="255.255.255.255" subnet="0" type="" interface="" container="">
255
            <ip address="%%adresse_ip_eth1"/>
256
        </extremite>
257
        <extremite zone="exterieur" name="exterieur" libelle="Zone entière" netmask="%%adresse_netmask_eth0" subnet="1" type="" interface="" container="">
258
            <ip address="%%adresse_ip_eth0"/>
259
        </extremite>
260
        <extremite zone="bastion" name="bdd" libelle="conteneur bdd" netmask="255.255.255.255" subnet="0" type="conteneur" interface="containers" container="bdd">
261
            <ip address="%%container_ip_bdd"/>
262
        </extremite>
263
        <extremite zone="exterieur" name="exterieur_admin" libelle="reseau autorise a administrer depuis l'exterieur" netmask="%%netmask_admin_eth0" subnet="1" type="" interface="" container="">
264
            <ip address="%%ip_admin_eth0"/>
265
        </extremite>
266
        <extremite zone="exterieur" name="exterieur_restreint" libelle="zone restreinte" netmask="%%adresse_netmask_eth0" subnet="1" type="" interface="" container="">
267
            <ip address="%%adresse_network_eth0"/>
268
        </extremite>
269
        <extremite zone="exterieur" name="clients_relp_rsyslog" libelle="clients de l'agrégateur de logs en relp" netmask="%%netmask_client_logs_relp" subnet="0" type="" interface="" container="">
270
            <ip address="%%adresses_ip_clients_logs_relp"/>
271
        </extremite>
272
        <extremite zone="exterieur" name="clients_tcp_rsyslog" libelle="clients de l'agrégateur de logs en tcp" netmask="%%netmask_client_logs_tcp" subnet="0" type="" interface="" container="">
273
            <ip address="%%adresses_ip_clients_logs_tcp"/>
274
        </extremite>
275
        <extremite zone="exterieur" name="clients_udp_rsyslog" libelle="clients de l'agrégateur de logs en udp" netmask="%%netmask_client_logs_udp" subnet="0" type="" interface="" container="">
276
            <ip address="%%adresses_ip_clients_logs_udp"/>
277
        </extremite>
278
        <extremite zone="bastion" name="bastion_exterieur" libelle="Bastion sur la zone exterieur" netmask="255.255.255.255" subnet="0" type="normal" interface="eth0" container="">
279
            <ip address="%%adresse_ip_eth0"/>
280
        </extremite>
281
        <extremite zone="exterieur" name="exterieur_backend_ead" libelle="reseau autorise a acceder au backend EAD depuis l'exterieur" netmask="%%netmask_frontend_ead_distant_eth0" subnet="1" type="" interface="" container="">
282
            <ip address="%%ip_frontend_ead_distant_eth0"/>
283
        </extremite>
284
        <extremite zone="bastion" name="internet_eth1" libelle="eth1 dans le conteneur internet" netmask="255.255.255.255" subnet="0" type="conteneur" interface="eth1" container="internet">
285
            <ip address="%%adresse_ip_eth1_proxy_link"/>
286
        </extremite>
287
        <extremite zone="bastion" name="reseau" libelle="conteneur reseau" netmask="255.255.255.255" subnet="0" type="conteneur" interface="containers" container="reseau">
288
            <ip address="%%container_ip_reseau"/>
289
        </extremite>
290
        <extremite zone="bastion" name="partage_eth1" libelle="eth1 dans le conteneur partage" netmask="255.255.255.255" subnet="0" type="conteneur" interface="eth1" container="partage">
291
            <ip address="%%adresse_ip_fichier_link"/>
292
        </extremite>
293
        <extremite zone="pedago" name="pedago_restreint" libelle="zone restreinte" netmask="%%adresse_netmask_eth1" subnet="1" type="" interface="" container="">
294
            <ip address="%%adresse_network_eth1"/>
295
        </extremite>
296
        <extremite zone="pedago" name="pedago_ssh" libelle="reseau autorise a se connecter a ssh depuis le reseau pedagogique" netmask="%%netmask_ssh_eth1" subnet="1" type="" interface="" container="">
297
            <ip address="%%ip_ssh_eth1"/>
298
        </extremite>
299
        <extremite zone="pedago" name="pedago" libelle="Zone entière" netmask="%%adresse_netmask_eth1" subnet="1" type="" interface="" container="">
300
            <ip address="%%adresse_ip_eth1"/>
301
        </extremite>
302
        <extremite zone="bastion" name="ltspserver_eth0" libelle="LTSP server" netmask="255.255.255.255" subnet="0" type="conteneur" interface="eth0" container="ltspserver">
303
            <ip address="%%adresse_ip_eclair_link"/>
304
        </extremite>
305
        <extremite zone="exterieur" name="exterieur_ssh" libelle="reseau autorise a se connecter a ssh" netmask="%%netmask_ssh_eth0" subnet="1" type="" interface="" container="">
306
            <ip address="%%ip_ssh_eth0"/>
307
        </extremite>
308
        <extremite zone="pedago" name="pedago_backend_ead" libelle="reseau autorise a acceder au backend EAD depuis le reseau pedagogique" netmask="%%netmask_frontend_ead_distant_eth1" subnet="1" type="" interface="" container="">
309
            <ip address="%%ip_frontend_ead_distant_eth1"/>
310
        </extremite>
311
        <extremite zone="bastion" name="bastion" libelle="Zone entière" netmask="255.255.255.255" subnet="1" type="" interface="" container="">
312
            <ip address="127.0.0.1"/>
313
        </extremite>
314
        <extremite zone="bastion" name="internet" libelle="conteneur internet" netmask="255.255.255.255" subnet="0" type="conteneur" interface="containers" container="internet">
315
            <ip address="%%container_ip_internet"/>
316
        </extremite>
317
        <extremite zone="pedago" name="pedago_admin" libelle="reseau autorise a administrer depuis le reseau pedagogique" netmask="%%netmask_admin_eth1" subnet="1" type="" interface="" container="">
318
            <ip address="%%ip_admin_eth1"/>
319
        </extremite>
320
        <extremite zone="exterieur" name="exterieur_bastion" libelle="IP de bastion sur la zone exterieur" netmask="255.255.255.255" subnet="0" type="" interface="" container="">
321
            <ip address="%%adresse_ip_eth0"/>
322
        </extremite>
323
        <extremite zone="pedago" name="client_nfs" libelle="Client NFS" netmask="255.255.255.255" subnet="0" type="normal" interface="" container="">
324
            <ip address="%%adresses_ip_clients_nfs"/>
325
        </extremite>
326
        <extremite zone="bastion" name="partage_eth1_broadcast" libelle="broadcast eth1 dans le conteneur partage" netmask="255.255.255.255" subnet="0" type="conteneur" interface="eth1" container="partage">
327
            <ip address="%%adresse_bcast_eth1_proxy_link"/>
328
        </extremite>
329
    </extremites>
330
    <ranges>
331
    </ranges>
332
    <user_groups>
333
    </user_groups>
334
    <applications>
335
    </applications>
336
    <flux-list>
337
        <flux zoneA="bastion" zoneB="exterieur">
338
            <montantes default_policy="0">
339
                <directive tag="ActiverNGINX" service="scribe-posh" priority="1" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="ouverture de posh a travers de nginx" ipsec="0" accept="0">
340
                    <source name="exterieur"/>
341
                    <destination name="bastion"/>
342
                </directive>
343
                <directive tag="ead_scribe" service="ead-scribe" priority="2" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="ouverture de l'EAD Scribe a travers de nginx" ipsec="0" accept="0">
344
                    <source name="exterieur"/>
345
                    <destination name="bastion"/>
346
                </directive>
347
                <directive tag="SSHDepuisEth0" service="ssh" priority="3" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="ssh exterieur vers Amon" ipsec="0" accept="0">
348
                    <source name="exterieur_ssh"/>
349
                    <destination name="bastion"/>
350
                </directive>
351
                <directive tag="AdminDepuisEth0" service="admin_amon" priority="4" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="administration exterieure vers Amon" ipsec="0" accept="0">
352
                    <source name="exterieur_admin"/>
353
                    <destination name="bastion"/>
354
                </directive>
355
                <directive tag="BackendEADDepuisEth0" service="ead_server" priority="5" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Acces backend EAD exterieure vers Amon" ipsec="0" accept="0">
356
                    <source name="exterieur_backend_ead"/>
357
                    <destination name="bastion"/>
358
                </directive>
359
                <directive tag="lightsquid0" service="lightsquid" priority="6" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="administration exterieure vers Amon" ipsec="0" accept="0">
360
                    <source name="exterieur_admin"/>
361
                    <destination name="bastion"/>
362
                </directive>
363
                <directive tag="eole_sso" service="eole-sso" priority="7" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
364
                    <source name="exterieur"/>
365
                    <destination name="bastion"/>
366
                </directive>
367
                <directive tag="revprox_sso" service="revprox-sso" priority="8" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="redirection du service EoleSSO par le proxy inverse" ipsec="0" accept="0">
368
                    <source name="exterieur"/>
369
                    <destination name="bastion"/>
370
                </directive>
371
                <directive service="ipsec" priority="9" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Autoriser ipsec" ipsec="0" accept="0">
372
                    <source name="exterieur"/>
373
                    <destination name="bastion"/>
374
                </directive>
375
                <directive tag="SSHDepuisEth0" service="gen_config" priority="10" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="gen_config exterieur vers Amon" ipsec="0" accept="0">
376
                    <source name="exterieur_ssh"/>
377
                    <destination name="bastion"/>
378
                </directive>
379
                <directive tag="ClientRsyslogRELP" service="rsyslog_RELP" priority="11" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
380
                    <source name="clients_relp_rsyslog"/>
381
                    <destination name="bastion"/>
382
                </directive>
383
                <directive tag="ClientRsyslogTCP" service="rsyslog_TCP" priority="12" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
384
                    <source name="clients_tcp_rsyslog"/>
385
                    <destination name="bastion"/>
386
                </directive>
387
                <directive tag="ClientRsyslogUDP" service="rsyslog_UDP" priority="13" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
388
                    <source name="clients_udp_rsyslog"/>
389
                    <destination name="bastion"/>
390
                </directive>
391
                <directive tag="autoriser la reception des mails depuis exterieur" service="smtp" priority="14" action="2" attrs="1" src_inv="0" dest_inv="0" serv_inv="0" libelle="autoriser la reception des mails depuis exterieur" ipsec="0" accept="0">
392
                    <source name="exterieur"/>
393
                    <destination name="reseau"/>
394
                </directive>
395
                <directive tag="AdminDepuisEth0" service="sympa-internet" priority="15" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="interface web sympa" ipsec="0" accept="0">
396
                    <source name="exterieur_admin"/>
397
                    <destination name="reseau"/>
398
                </directive>
399
            </montantes>
400
            <descendantes default_policy="1">
401
            </descendantes>
402
        </flux>
403
        <flux zoneA="exterieur" zoneB="pedago">
404
            <montantes default_policy="0">
405
            </montantes>
406
            <descendantes default_policy="1">
407
                <directive service="tous" priority="1" action="16" attrs="0" nat_extr="exterieur_bastion" nat_port="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
408
                    <source name="pedago_restreint"/>
409
                    <destination name="exterieur"/>
410
                </directive>
411
                <directive tag="Interdiction des forums" service="gr_forum" priority="2" action="1" attrs="1" src_inv="0" dest_inv="0" serv_inv="0" libelle="pedago -> exterieur : interdire les protocoles de news, forums ..." ipsec="0" accept="0">
412
                    <source name="pedago"/>
413
                    <destination name="exterieur"/>
414
                </directive>
415
                <directive tag="Interdire les connexions FTP" service="gr_ftp" priority="3" action="1" attrs="1" src_inv="0" dest_inv="0" serv_inv="0" libelle="Interdire les connexions FTP" ipsec="0" accept="0">
416
                    <source name="pedago"/>
417
                    <destination name="exterieur"/>
418
                </directive>
419
                <directive tag="Interdire l'utilisation des dialogues en direct" service="gr_irc" priority="4" action="1" attrs="1" src_inv="0" dest_inv="0" serv_inv="0" libelle="pedago -> exterieur : interdire les protocoles de discussion en ligne (irc ...)" ipsec="0" accept="0">
420
                    <source name="pedago"/>
421
                    <destination name="exterieur"/>
422
                </directive>
423
                <directive tag="Interdiction des protocoles de messagerie" service="gr_messagerie" priority="5" action="1" attrs="1" src_inv="0" dest_inv="0" serv_inv="0" libelle="pedago -> exterieur : interdire les protocoles de messagerie (pop, imap ...)" ipsec="0" accept="0">
424
                    <source name="pedago"/>
425
                    <destination name="exterieur"/>
426
                </directive>
427
                <directive tag="Internet restreint" service="gr_restreint" priority="6" action="1" attrs="1" src_inv="0" dest_inv="0" serv_inv="0" libelle="pedago -> exterieur : tout interdire (sauf le web via le proxy)" ipsec="0" accept="0">
428
                    <source name="pedago"/>
429
                    <destination name="exterieur"/>
430
                </directive>
431
                <directive tag="ProxyBypass1" service="gr_redirection_proxy" priority="7" action="4" attrs="17" nat_port="3128" src_inv="0" dest_inv="0" serv_inv="0" libelle="Redirection des flux http avec proxy alternatif" ipsec="0" accept="0">
432
                    <source name="pedago"/>
433
                    <destination name="exterieur"/>
434
                    <exception name="" ip="" eolvar="%%proxy_bypass_src_network_eth1/%%calc_classe(%%proxy_bypass_src_netmask_eth1)" src="1" dest="0"/>
435
                    <exception name="" ip="" eolvar="%%proxy_bypass_network_eth1/%%calc_classe(%%proxy_bypass_netmask_eth1)" src="0" dest="1"/>
436
                    <exception name="" ip="" eolvar="%%proxy_bypass_domain_eth1" src="0" dest="1"/>
437
                </directive>
438
                <directive tag="ProxyBypass1" service="http" priority="8" action="4" attrs="17" nat_port="81" src_inv="0" dest_inv="1" serv_inv="0" libelle="Redirection des flux http sans proxy" ipsec="0" accept="0">
439
                    <source name="pedago"/>
440
                    <destination name="exterieur_bastion"/>
441
                    <exception name="" ip="" eolvar="%%proxy_bypass_src_network_eth1/%%calc_classe(%%proxy_bypass_src_netmask_eth1)" src="1" dest="0"/>
442
                    <exception name="" ip="" eolvar="%%proxy_bypass_network_eth1/%%calc_classe(%%proxy_bypass_netmask_eth1)" src="0" dest="1"/>
443
                    <exception name="" ip="" eolvar="%%proxy_bypass_domain_eth1" src="0" dest="1"/>
444
                </directive>
445
                <directive tag="ProxyBypass1" service="gr_redirection_https" priority="9" action="4" attrs="17" nat_port="82" src_inv="0" dest_inv="0" serv_inv="0" libelle="Redirection des flux https sans proxy vers une page d'erreur" ipsec="0" accept="0">
446
                    <source name="pedago"/>
447
                    <destination name="exterieur"/>
448
                    <exception name="" ip="" eolvar="%%proxy_bypass_src_network_eth1/%%calc_classe(%%proxy_bypass_src_netmask_eth1)" src="1" dest="0"/>
449
                    <exception name="" ip="" eolvar="%%proxy_bypass_network_eth1/%%calc_classe(%%proxy_bypass_netmask_eth1)" src="0" dest="1"/>
450
                    <exception name="" ip="" eolvar="%%proxy_bypass_domain_eth1" src="0" dest="1"/>
451
                </directive>
452
                <directive tag="ForceProxy1" service="gr_redirection_proxy" priority="10" action="4" attrs="17" nat_port="3128" src_inv="0" dest_inv="0" serv_inv="0" libelle="Redirection des flux http avec proxy alternatif" ipsec="0" accept="0">
453
                    <source name="pedago"/>
454
                    <destination name="exterieur"/>
455
                    <exception name="" ip="" eolvar="%%proxy_bypass_src_network_eth1/%%calc_classe(%%proxy_bypass_src_netmask_eth1)" src="1" dest="0"/>
456
                    <exception name="" ip="" eolvar="%%proxy_bypass_domain_eth1" src="0" dest="1"/>
457
                </directive>
458
                <directive tag="ForceProxy1" service="http" priority="11" action="4" attrs="17" nat_port="81" src_inv="0" dest_inv="1" serv_inv="0" libelle="Redirection des flux http sans proxy vers une page d'erreur" ipsec="0" accept="0">
459
                    <source name="pedago"/>
460
                    <destination name="exterieur_bastion"/>
461
                    <exception name="" ip="" eolvar="%%proxy_bypass_src_network_eth1/%%calc_classe(%%proxy_bypass_src_netmask_eth1)" src="1" dest="0"/>
462
                    <exception name="" ip="" eolvar="%%proxy_bypass_domain_eth1" src="0" dest="1"/>
463
                </directive>
464
                <directive tag="ForceProxy1" service="gr_redirection_https" priority="12" action="4" attrs="17" nat_port="82" src_inv="0" dest_inv="0" serv_inv="0" libelle="Redirection des flux https sans proxy vers une page d'erreur" ipsec="0" accept="0">
465
                    <source name="pedago"/>
466
                    <destination name="exterieur"/>
467
                    <exception name="" ip="" eolvar="%%proxy_bypass_src_network_eth1/%%calc_classe(%%proxy_bypass_src_netmask_eth1)" src="1" dest="0"/>
468
                    <exception name="" ip="" eolvar="%%proxy_bypass_domain_eth1" src="0" dest="1"/>
469
                </directive>
470
            </descendantes>
471
        </flux>
472
        <flux zoneA="bastion" zoneB="pedago">
473
            <montantes default_policy="0">
474
                <directive tag="SSHDepuisEth1" service="ssh" priority="1" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="ssh pedago vers Amon" ipsec="0" accept="0">
475
                    <source name="pedago_ssh"/>
476
                    <destination name="bastion"/>
477
                </directive>
478
                <directive tag="AdminDepuisEth1" service="admin_amon" priority="2" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="administration pedago vers Amon" ipsec="0" accept="0">
479
                    <source name="pedago_admin"/>
480
                    <destination name="bastion"/>
481
                </directive>
482
                <directive tag="lightsquid1" service="lightsquid" priority="3" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="administration pedago vers Amon" ipsec="0" accept="0">
483
                    <source name="pedago_admin"/>
484
                    <destination name="bastion"/>
485
                </directive>
486
                <directive service="dns-tcp" priority="4" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
487
                    <source name="pedago"/>
488
                    <destination name="internet_eth1"/>
489
                </directive>
490
                <directive service="dns-udp" priority="5" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
491
                    <source name="pedago"/>
492
                    <destination name="internet_eth1"/>
493
                </directive>
494
                <directive tag="auth_nufw" service="nuauth" priority="6" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="autoriser l'acces a Nuauth" ipsec="0" accept="0">
495
                    <source name="pedago"/>
496
                    <destination name="bastion"/>
497
                </directive>
498
                <directive tag="eole_sso" service="eole-sso" priority="7" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
499
                    <source name="pedago"/>
500
                    <destination name="bastion"/>
501
                </directive>
502
                <directive service="proxy" priority="8" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
503
                    <source name="pedago"/>
504
                    <destination name="internet_eth1"/>
505
                </directive>
506
                <directive tag="Activer squid2" service="proxy2" priority="9" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
507
                    <source name="pedago"/>
508
                    <destination name="internet_eth1"/>
509
                </directive>
510
                <directive tag="cntlm" service="cntlm" priority="10" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
511
                    <source name="pedago"/>
512
                    <destination name="internet_eth1"/>
513
                </directive>
514
                <directive tag="SSHDepuisEth1" service="gen_config" priority="11" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="gen_config pedago vers Amon" ipsec="0" accept="0">
515
                    <source name="pedago_ssh"/>
516
                    <destination name="bastion"/>
517
                </directive>
518
                <directive tag="BackendEADDepuisEth1" service="ead_server" priority="12" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Acces backend EAD pedago vers Amon" ipsec="0" accept="0">
519
                    <source name="pedago_backend_ead"/>
520
                    <destination name="bastion"/>
521
                </directive>
522
                <directive tag="ActiverRadiuseth1" service="gr_radius" priority="13" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="raduis admin vers Amon" ipsec="0" accept="0">
523
                    <source name="pedago"/>
524
                    <destination name="bastion"/>
525
                </directive>
526
                <directive service="http" priority="14" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Autorisation reverse proxy + WPAD" ipsec="0" accept="0">
527
                    <source name="pedago"/>
528
                    <destination name="bastion_exterieur"/>
529
                </directive>
530
                <directive tag="activer_ldap" service="ldap" priority="15" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
531
                    <source name="pedago"/>
532
                    <destination name="bdd"/>
533
                </directive>
534
                <directive tag="activer_ldaps" service="ldaps" priority="16" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
535
                    <source name="pedago"/>
536
                    <destination name="bdd"/>
537
                </directive>
538
                <directive service="ntp" priority="17" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="autoriser les requetes ntp" ipsec="0" accept="0">
539
                    <source name="pedago"/>
540
                    <destination name="bastion"/>
541
                </directive>
542
                <directive tag="AdminDepuisEth1" service="sympa-internet" priority="18" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="interface web sympa" ipsec="0" accept="0">
543
                    <source name="pedago_admin"/>
544
                    <destination name="reseau"/>
545
                </directive>
546
                <directive service="sympa-restreint" priority="19" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="interface web sympa" ipsec="0" accept="0">
547
                    <source name="pedago"/>
548
                    <destination name="reseau"/>
549
                </directive>
550
                <directive tag="activer_nfs" service="nfs" priority="20" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Activer NFS depuis les clients" ipsec="0" accept="0">
551
                    <source name="client_nfs"/>
552
                    <destination name="bastion"/>
553
                </directive>
554
                <directive tag="activer_courrier_imap" service="imap" priority="21" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
555
                    <source name="pedago"/>
556
                    <destination name="reseau"/>
557
                </directive>
558
                <directive tag="activer_courrier_imap" service="imap4-ssl" priority="22" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
559
                    <source name="pedago"/>
560
                    <destination name="reseau"/>
561
                </directive>
562
                <directive tag="activer_courrier_pop" service="pop" priority="23" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
563
                    <source name="pedago"/>
564
                    <destination name="reseau"/>
565
                </directive>
566
                <directive tag="activer_courrier_pop" service="pop3s" priority="24" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
567
                    <source name="pedago"/>
568
                    <destination name="reseau"/>
569
                </directive>
570
                <directive service="smtp" priority="25" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
571
                    <source name="pedago"/>
572
                    <destination name="reseau"/>
573
                </directive>
574
                <directive service="smtps" priority="26" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
575
                    <source name="pedago"/>
576
                    <destination name="reseau"/>
577
                </directive>
578
                <directive tag="activer_xmpp" service="xmpp" priority="27" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
579
                    <source name="pedago"/>
580
                    <destination name="reseau"/>
581
                </directive>
582
                <directive tag="activer_xmpp" service="xmpp-ssl" priority="28" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
583
                    <source name="pedago"/>
584
                    <destination name="reseau"/>
585
                </directive>
586
                <directive tag="activer_tftp" service="tftpd-hpa" priority="29" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0">
587
                    <source name="pedago"/>
588
                    <destination name="bdd"/>
589
                </directive>
590
                <directive tag="activer_cups1" service="cups" priority="30" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="interface web CUPS" ipsec="0" accept="0">
591
                    <source name="pedago_admin"/>
592
                    <destination name="partage_eth1"/>
593
                </directive>
594
                <directive service="scribe-controlevnc" priority="31" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Controle VNC" ipsec="0" accept="0">
595
                    <source name="pedago"/>
596
                    <destination name="partage_eth1"/>
597
                </directive>
598
                <directive tag="activer_proftpd" service="ftp" priority="32" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Controle VNC" ipsec="0" accept="0">
599
                    <source name="pedago"/>
600
                    <destination name="partage_eth1"/>
601
                </directive>
602
                <directive service="samba" priority="33" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Controle VNC" ipsec="0" accept="0">
603
                    <source name="pedago"/>
604
                    <destination name="partage_eth1"/>
605
                </directive>
606
                <directive service="samba" priority="34" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Controle VNC" ipsec="0" accept="0">
607
                    <source name="pedago"/>
608
                    <destination name="partage_eth1_broadcast"/>
609
                </directive>
610
                <directive service="echo-request" priority="35" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Autorise le ping vers le conteneur" ipsec="0" accept="0">
611
                    <source name="pedago"/>
612
                    <destination name="partage_eth1"/>
613
                </directive>
614
                <directive service="echo-request" priority="36" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="Autorise le ping vers le conteneur" ipsec="0" accept="0">
615
                    <source name="pedago"/>
616
                    <destination name="internet_eth1"/>
617
                </directive>
618
                <directive tag="GaspachoEth1" service="gaspacho" priority="37" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Autoriser l'accès à Gaspacho" ipsec="0" accept="0">
619
                    <source name="pedago"/>
620
                    <destination name="partage_eth1"/>
621
                </directive>
622
                <directive tag="activer_eclair_amonecole" service="amonecole-eclair" priority="38" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Open Eclair ports on AmonEcole" ipsec="0" accept="0">
623
                    <source name="pedago"/>
624
                    <destination name="ltspserver_eth0"/>
625
                </directive>
626
                <directive tag="activer_eclair_amonecole" service="amonecole-eclair-partage" priority="39" action="2" attrs="17" src_inv="0" dest_inv="0" serv_inv="0" libelle="Open Gaspacho and TFTPD for Eclair on AmonEcole" ipsec="0" accept="0">
627
                    <source name="pedago"/>
628
                    <destination name="partage_eth1"/>
629
                </directive>
630
            </montantes>
631
            <descendantes default_policy="1">
632
            </descendantes>
633
        </flux>
634
    </flux-list>
635
</firewall>