Project

General

Profile

Tâche #12856

Scénario #12871: Ajouter la gestion du parefeu client depuis la ligne de commande du serveur

Modifier cliscribe.py pour y ajouter la gestion du parefeu

Added by Klaas TJEBBES over 5 years ago. Updated over 5 years ago.

Status:
Fermé
Priority:
Normal
Assigned To:
Start date:
09/08/2015
Due date:
% Done:

100%

Estimated time:
1.00 h
Spent time:
Remaining (hours):
0.0

Description

Dans /usr/share/eole/controlevnc/cliscribe.py, ajouter une action "-fw" (comme il existe déjà "-killproc", "-shutdown", "-execute", "-executeuser", "-vnc").

cliscribe.py -fw FW_ACTION         FW_ACTION : INIT|ADD::rule|DEL::Nom|SETMODE::<in>;;<out>|ACTIVATE::True|False
                            * INIT initialise les règles de bases (fait une simple initalisation, ne lit pas "liste_fwregles.eol")
                            * ADD::rule
                                rule='Nom;; ip_src=XX;;ip_dst=XX;;action=XX;;proto=XX;;port_dst=XX;;program=XX'
                                    - ip_src/dst = me|any|<ip>
                                    - action=allow|block
                                    - proto=tcp|udp|icmp|any
                                (Ex. 'ADD::TOTO;;ip_src=me;;ip_dst=any;;action=block;;proto=udp;;port_dst=123')
                                (Ex. 'ADD::TOTO;;ip_src=me;;ip_dst=any;;action=block;;proto=any;;program=notepad.exe')
                            * DEL::Nom
                                (Ex. 'DEL::TOTO')
                            * SETMODE::<in>;;<out>
                                <in>=allow|block
                                <out>=allow|block
                                (Ex. "SETMODE::block;;allow")
                            * ACTIVATE::True|False
r

Associated revisions

Revision d5974cdd (diff)
Added by Klaas TJEBBES over 5 years ago

Modifier cliscribe.py pour y ajouter la gestion du parefeu FIXES #12856 @1h

Revision 8a0dffb6 (diff)
Added by Klaas TJEBBES over 5 years ago

Modifier cliscribe.py pour y ajouter la gestion du parefeu FIXES #12856

History

#1 Updated by Klaas TJEBBES over 5 years ago

  • Subject changed from Ajouter la gestion du parefeu client depuis la ligne de commande du serveur to Modifier cliscribe.py pour y ajouter la gestion du parefeu
  • Description updated (diff)

#2 Updated by Klaas TJEBBES over 5 years ago

  • Description updated (diff)

#3 Updated by Klaas TJEBBES over 5 years ago

  • Tracker changed from Evolution to Tâche

#4 Updated by Klaas TJEBBES over 5 years ago

  • Parent task set to #12871

#5 Updated by Klaas TJEBBES over 5 years ago

  • Status changed from Nouveau to Résolu
  • % Done changed from 0 to 100

#7 Updated by Emmanuel GARETTE over 5 years ago

  • Assigned To set to Klaas TJEBBES
  • Estimated time set to 1.00 h
  • Remaining (hours) set to 0.25

#8 Updated by Emmanuel GARETTE over 5 years ago

Je ne trouve aucun paquet, demande non testable.

#9 Updated by Fabrice Barconnière over 5 years ago

  • Remaining (hours) changed from 0.25 to 0.0

intégration poste avec FW activé dans domaine + désactivation du FW :

root@scribe:~# /usr/share/eole/controlevnc/cliscribe.py -f ACTIVATE::False 10.1.2.50
firewall ACTIVATE::False

FW passe bien en état désactivé coté client.

#10 Updated by Fabrice Barconnière over 5 years ago

  • Status changed from Résolu to Fermé

Also available in: Atom PDF