<directiveservice="apt-cacher-ng"priority="40"action="2"attrs="0"mark_operator="None"mark_value=""src_inv="0"dest_inv="0"serv_inv="0"libelle="pas de description"ipsec="0"accept="0">
<sourcename="pedago"/>
<sourcename="admin"/>
<destinationname="bastion"/>
</directive>
</montantes>
<descendantesdefault_policy="1">
</descendantes>
</flux>
<fluxzoneA="bastion"zoneB="admin">
<montantesdefault_policy="0">
<directiveservice="registry"priority="41"action="2"attrs="0"src_inv="0"dest_inv="0"serv_inv="0"libelle="pas de description"ipsec="0"accept="0">
<sourcename="admin"/>
<destinationname="partage_eth2"/>
</directive>
</montantes>
<descendantesdefault_policy="1">
</descendantes>
</flux>
<fluxzoneA="bastion"zoneB="admin">
<montantesdefault_policy="0">
<directiveservice="cups"priority="42"action="2"attrs="0"src_inv="0"dest_inv="0"serv_inv="0"libelle="pas de description"ipsec="0"accept="0">
<sourcename="admin"/>
<destinationname="partage_eth2"/>
</directive>
</montantes>
<descendantesdefault_policy="1">
</descendantes>
</flux>
<fluxzoneA="bastion"zoneB="admin">
<montantesdefault_policy="0">
<directiveservice="apt-cacher-ng"priority="40"action="2"attrs="0"mark_operator="None"mark_value=""src_inv="0"dest_inv="0"serv_inv="0"libelle="pas de description"ipsec="0"accept="0">
<extremitecontainer=""interface=""libelle="reseau autorise a se connecter a ssh"name="exterieur_ssh"netmask="%%netmask_ssh_eth0"subnet="1"type=""zone="exterieur">
<extremitecontainer=""interface="eth0"libelle="Bastion sur la zone exterieur"name="bastion_exterieur"netmask="255.255.255.255"subnet="0"type="normal"zone="bastion">
<ipaddress="%%adresse_ip_eth0"/>
</extremite>
<extremitecontainer=""interface=""libelle="reseau autorise a administrer depuis l'exterieur"name="exterieur_admin"netmask="%%netmask_admin_eth0"subnet="1"type=""zone="exterieur">
<ipaddress="%%ip_admin_eth0"/>
</extremite>
<extremitecontainer=""interface=""libelle="reseau autorise a acceder au backend EAD depuis l'exterieur"name="exterieur_backend_ead"netmask="%%netmask_frontend_ead_distant_eth0"subnet="1"type=""zone="exterieur">
<ipaddress="%%ip_frontend_ead_distant_eth0"/>
</extremite>
<extremitecontainer=""interface=""libelle="IP de bastion sur la zone exterieur"name="exterieur_bastion"netmask="255.255.255.255"subnet="0"type=""zone="exterieur">
<extremitecontainer=""interface=""libelle="reseau autorise a se connecter a ssh depuis le reseau pedagogique"name="pedago_ssh"netmask="%%netmask_ssh_eth1"subnet="1"type=""zone="pedago">
<extremitecontainer=""interface=""libelle="reseau autorise a administrer depuis le reseau pedagogique"name="pedago_admin"netmask="%%netmask_admin_eth1"subnet="1"type=""zone="pedago">
<ipaddress="%%ip_admin_eth1"/>
</extremite>
<extremitecontainer=""interface=""libelle="reseau autorise a acceder au backend EAD depuis le reseau pedagogique"name="pedago_backend_ead"netmask="%%netmask_frontend_ead_distant_eth1"subnet="1"type=""zone="pedago">
<ipaddress="%%ip_frontend_ead_distant_eth1"/>
</extremite>
<extremitecontainer="internet"interface="eth1"libelle="eth1 dans le conteneur internet"name="internet_eth1"netmask="255.255.255.255"subnet="0"type="conteneur"zone="bastion">
<ipaddress="%%adresse_ip_eth1_proxy_link"/>
</extremite>
<extremitecontainer=""interface=""libelle="reseau autorise a se connecter a ssh depuis le reseau administratif"name="admin_ssh"netmask="%%netmask_ssh_eth2"subnet="1"type=""zone="admin">
<extremitecontainer=""interface=""libelle="reseau autorise a administrer depuis le reseau administratif"name="admin_admin"netmask="%%netmask_admin_eth2"subnet="1"type=""zone="admin">
<ipaddress="%%ip_admin_eth2"/>
</extremite>
<extremitecontainer=""interface=""libelle="reseau autorise a acceder au backend EAD depuis le reseau administratif"name="admin_backend_ead"netmask="%%netmask_frontend_ead_distant_eth2"subnet="1"type=""zone="admin">
<ipaddress="%%ip_frontend_ead_distant_eth2"/>
</extremite>
<extremitecontainer="internet"interface="eth2"libelle="eth2 dans le conteneur internet"name="internet_eth2"netmask="255.255.255.255"subnet="0"type="conteneur"zone="bastion">
<ipaddress="%%adresse_ip_eth2_proxy_link"/>
</extremite>
<extremitecontainer=""interface=""libelle="clients de l'agrégateur de logs en udp"name="clients_udp_rsyslog"netmask="%%netmask_client_logs_udp"subnet="0"type=""zone="exterieur">
<ipaddress="%%adresses_ip_clients_logs_udp"/>
</extremite>
<extremitecontainer=""interface=""libelle="clients de l'agrégateur de logs en tcp"name="clients_tcp_rsyslog"netmask="%%netmask_client_logs_tcp"subnet="0"type=""zone="exterieur">
<ipaddress="%%adresses_ip_clients_logs_tcp"/>
</extremite>
<extremitecontainer=""interface=""libelle="clients de l'agrégateur de logs en relp"name="clients_relp_rsyslog"netmask="%%netmask_client_logs_relp"subnet="0"type=""zone="exterieur">
<ipaddress="%%adresses_ip_clients_logs_relp"/>
</extremite>
<extremitecontainer="partage"interface="eth1"libelle="eth1 dans le conteneur partage"name="partage_eth1"netmask="255.255.255.255"subnet="0"type="conteneur"zone="bastion">
<ipaddress="%%adresse_ip_fichier_link"/>
</extremite>
<extremitecontainer="partage"interface="eth1"libelle="broadcast eth1 dans le conteneur partage"name="partage_eth1_broadcast"netmask="255.255.255.255"subnet="0"type="conteneur"zone="bastion">
<extremitecontainer="ltspserver"interface="containers"libelle="LTSP on internal bridge"name="ltspserver"netmask="255.255.255.255"subnet="0"type="conteneur"zone="bastion">
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="ouverture de posh a travers de nginx"priority="1"serv_inv="0"service="scribe-posh"src_inv="0"tag="ActiverNGINX">
<sourcename="exterieur"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="ouverture de l'EAD Scribe a travers de nginx"priority="2"serv_inv="0"service="ead-scribe"src_inv="0"tag="ead_scribe">
<sourcename="exterieur"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="ssh exterieur vers Amon"priority="3"serv_inv="0"service="ssh"src_inv="0"tag="SSHDepuisEth0">
<sourcename="exterieur_ssh"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="administration exterieure vers Amon"priority="4"serv_inv="0"service="admin_amon"src_inv="0"tag="AdminDepuisEth0">
<sourcename="exterieur_admin"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="Acces backend EAD exterieure vers Amon"priority="5"serv_inv="0"service="ead_server"src_inv="0"tag="BackendEADDepuisEth0">
<sourcename="exterieur_backend_ead"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="administration exterieure vers Amon"priority="6"serv_inv="0"service="lightsquid"src_inv="0"tag="lightsquid0">
<sourcename="exterieur_admin"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="7"serv_inv="0"service="eole-sso"src_inv="0"tag="eole_sso">
<sourcename="exterieur"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="redirection du service EoleSSO par le proxy inverse"priority="8"serv_inv="0"service="revprox-sso"src_inv="0"tag="revprox_sso">
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="gen_config exterieur vers Amon"priority="10"serv_inv="0"service="gen_config"src_inv="0"tag="SSHDepuisEth0">
<sourcename="exterieur_ssh"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="11"serv_inv="0"service="rsyslog_RELP"src_inv="0"tag="ClientRsyslogRELP">
<sourcename="clients_relp_rsyslog"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="12"serv_inv="0"service="rsyslog_TCP"src_inv="0"tag="ClientRsyslogTCP">
<sourcename="clients_tcp_rsyslog"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="13"serv_inv="0"service="rsyslog_UDP"src_inv="0"tag="ClientRsyslogUDP">
<sourcename="clients_udp_rsyslog"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="1"dest_inv="0"ipsec="0"libelle="autoriser la reception des mails depuis exterieur"priority="14"serv_inv="0"service="smtp"src_inv="0"tag="autoriser la reception des mails depuis exterieur">
<sourcename="exterieur"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="interface web sympa"priority="15"serv_inv="0"service="sympa-internet"src_inv="0"tag="AdminDepuisEth0">
<sourcename="exterieur_admin"/>
<destinationname="reseau"/>
</directive>
</montantes>
<descendantesdefault_policy="1">
</descendantes>
</flux>
<fluxzoneA="exterieur"zoneB="pedago">
<montantesdefault_policy="0">
</montantes>
<descendantesdefault_policy="1">
<directiveaccept="0"action="16"attrs="0"dest_inv="0"ipsec="0"libelle="pas de description"nat_extr="exterieur_bastion"nat_port="0"priority="1"serv_inv="0"service="tous"src_inv="0">
<sourcename="pedago_restreint"/>
<destinationname="exterieur"/>
</directive>
<directiveaccept="0"action="1"attrs="1"dest_inv="0"ipsec="0"libelle="pedago -> exterieur : interdire les protocoles de news, forums ..."priority="2"serv_inv="0"service="gr_forum"src_inv="0"tag="Interdiction des forums">
<sourcename="pedago"/>
<destinationname="exterieur"/>
</directive>
<directiveaccept="0"action="1"attrs="1"dest_inv="0"ipsec="0"libelle="Interdire les connexions FTP"priority="3"serv_inv="0"service="gr_ftp"src_inv="0"tag="Interdire les connexions FTP">
<sourcename="pedago"/>
<destinationname="exterieur"/>
</directive>
<directiveaccept="0"action="1"attrs="1"dest_inv="0"ipsec="0"libelle="pedago -> exterieur : interdire les protocoles de discussion en ligne (irc ...)"priority="4"serv_inv="0"service="gr_irc"src_inv="0"tag="Interdire l'utilisation des dialogues en direct">
<sourcename="pedago"/>
<destinationname="exterieur"/>
</directive>
<directiveaccept="0"action="1"attrs="1"dest_inv="0"ipsec="0"libelle="pedago -> exterieur : interdire les protocoles de messagerie (pop, imap ...)"priority="5"serv_inv="0"service="gr_messagerie"src_inv="0"tag="Interdiction des protocoles de messagerie">
<sourcename="pedago"/>
<destinationname="exterieur"/>
</directive>
<directiveaccept="0"action="1"attrs="1"dest_inv="0"ipsec="0"libelle="pedago -> exterieur : tout interdire (sauf le web via le proxy)"priority="6"serv_inv="0"service="gr_restreint"src_inv="0"tag="Internet restreint">
<sourcename="pedago"/>
<destinationname="exterieur"/>
</directive>
<directiveaccept="0"action="4"attrs="17"dest_inv="0"ipsec="0"libelle="Redirection des flux http avec proxy alternatif"nat_port="3128"priority="7"serv_inv="0"service="gr_redirection_proxy"src_inv="0"tag="ProxyBypass1">
<directiveaccept="0"action="4"attrs="17"dest_inv="1"ipsec="0"libelle="Redirection des flux http sans proxy"nat_port="81"priority="8"serv_inv="0"service="http"src_inv="0"tag="ProxyBypass1">
<directiveaccept="0"action="4"attrs="17"dest_inv="0"ipsec="0"libelle="Redirection des flux https sans proxy vers une page d'erreur"nat_port="82"priority="9"serv_inv="0"service="gr_redirection_https"src_inv="0"tag="ProxyBypass1">
<directiveaccept="0"action="4"attrs="17"dest_inv="0"ipsec="0"libelle="Redirection des flux http avec proxy alternatif"nat_port="3128"priority="10"serv_inv="0"service="gr_redirection_proxy"src_inv="0"tag="ForceProxy1">
<directiveaccept="0"action="4"attrs="17"dest_inv="1"ipsec="0"libelle="Redirection des flux http sans proxy vers une page d'erreur"nat_port="81"priority="11"serv_inv="0"service="http"src_inv="0"tag="ForceProxy1">
<directiveaccept="0"action="4"attrs="17"dest_inv="0"ipsec="0"libelle="Redirection des flux https sans proxy vers une page d'erreur"nat_port="82"priority="12"serv_inv="0"service="gr_redirection_https"src_inv="0"tag="ForceProxy1">
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="ssh pedago vers Amon"priority="1"serv_inv="0"service="ssh"src_inv="0"tag="SSHDepuisEth1">
<sourcename="pedago_ssh"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="administration pedago vers Amon"priority="2"serv_inv="0"service="admin_amon"src_inv="0"tag="AdminDepuisEth1">
<sourcename="pedago_admin"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="administration pedago vers Amon"priority="3"serv_inv="0"service="lightsquid"src_inv="0"tag="lightsquid1">
<sourcename="pedago_admin"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="pas de description"priority="4"serv_inv="0"service="dns-tcp"src_inv="0">
<sourcename="pedago"/>
<destinationname="internet_eth1"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="pas de description"priority="5"serv_inv="0"service="dns-udp"src_inv="0">
<sourcename="pedago"/>
<destinationname="internet_eth1"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="autoriser l'acces a Nuauth"priority="6"serv_inv="0"service="nuauth"src_inv="0"tag="auth_nufw">
<sourcename="pedago"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="7"serv_inv="0"service="eole-sso"src_inv="0"tag="eole_sso">
<sourcename="pedago"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="pas de description"priority="8"serv_inv="0"service="proxy"src_inv="0">
<sourcename="pedago"/>
<destinationname="internet_eth1"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="9"serv_inv="0"service="proxy2"src_inv="0"tag="Activer squid2">
<sourcename="pedago"/>
<destinationname="internet_eth1"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="10"serv_inv="0"service="cntlm"src_inv="0"tag="cntlm">
<sourcename="pedago"/>
<destinationname="internet_eth1"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="gen_config pedago vers Amon"priority="11"serv_inv="0"service="gen_config"src_inv="0"tag="SSHDepuisEth1">
<sourcename="pedago_ssh"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="Acces backend EAD pedago vers Amon"priority="12"serv_inv="0"service="ead_server"src_inv="0"tag="BackendEADDepuisEth1">
<sourcename="pedago_backend_ead"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="raduis admin vers Amon"priority="13"serv_inv="0"service="gr_radius"src_inv="0"tag="ActiverRadiuseth1">
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="Autoriser ntp depuis pedago"priority="15"serv_inv="0"service="ntp"src_inv="0">
<sourcename="pedago"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="16"serv_inv="0"service="ldap"src_inv="0"tag="activer_ldap">
<sourcename="pedago"/>
<destinationname="bdd"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="17"serv_inv="0"service="ldaps"src_inv="0"tag="activer_ldaps">
<sourcename="pedago"/>
<destinationname="bdd"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="interface web sympa"priority="18"serv_inv="0"service="sympa-internet"src_inv="0"tag="AdminDepuisEth1">
<sourcename="pedago_admin"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="interface web sympa"priority="19"serv_inv="0"service="sympa-restreint"src_inv="0">
<sourcename="pedago"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="Activer NFS depuis les clients"priority="20"serv_inv="0"service="nfs"src_inv="0"tag="activer_nfs">
<sourcename="client_nfs"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="21"serv_inv="0"service="imap"src_inv="0"tag="activer_courrier_imap">
<sourcename="pedago"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="22"serv_inv="0"service="imap4-ssl"src_inv="0"tag="activer_courrier_imap">
<sourcename="pedago"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="23"serv_inv="0"service="pop"src_inv="0"tag="activer_courrier_pop">
<sourcename="pedago"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="24"serv_inv="0"service="pop3s"src_inv="0"tag="activer_courrier_pop">
<sourcename="pedago"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="pas de description"priority="25"serv_inv="0"service="smtp"src_inv="0">
<sourcename="pedago"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="pas de description"priority="26"serv_inv="0"service="smtps"src_inv="0">
<sourcename="pedago"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="27"serv_inv="0"service="xmpp"src_inv="0"tag="activer_xmpp">
<sourcename="pedago"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="28"serv_inv="0"service="xmpp-ssl"src_inv="0"tag="activer_xmpp">
<sourcename="pedago"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="29"serv_inv="0"service="tftpd-hpa"src_inv="0"tag="activer_tftp">
<sourcename="pedago"/>
<destinationname="bdd"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="interface web CUPS"priority="30"serv_inv="0"service="cups"src_inv="0"tag="activer_cups1">
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="Autorise le ping vers le conteneur"priority="35"serv_inv="0"service="echo-request"src_inv="0">
<sourcename="pedago"/>
<destinationname="partage_eth1"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="Autorise le ping vers le conteneur"priority="36"serv_inv="0"service="echo-request"src_inv="0">
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="Open Eclair ports on AmonEcole"priority="38"serv_inv="0"service="amonecole-eclair"src_inv="0"tag="activer_eclair_amonecole">
<sourcename="pedago"/>
<destinationname="ltspserver_eth0"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="Open Gaspacho and TFTPD for Eclair on AmonEcole"priority="39"serv_inv="0"service="amonecole-eclair-partage"src_inv="0"tag="activer_eclair_amonecole">
<sourcename="pedago"/>
<destinationname="partage_eth1"/>
</directive>
</montantes>
<descendantesdefault_policy="1">
</descendantes>
</flux>
<fluxzoneA="exterieur"zoneB="admin">
<montantesdefault_policy="0">
</montantes>
<descendantesdefault_policy="1">
<directiveaccept="0"action="16"attrs="0"dest_inv="0"ipsec="0"libelle="pas de description"nat_extr="exterieur_bastion"nat_port="0"priority="1"serv_inv="0"service="tous"src_inv="0">
<sourcename="admin_restreint"/>
<destinationname="exterieur"/>
</directive>
<directiveaccept="0"action="1"attrs="1"dest_inv="0"ipsec="0"libelle="admin -> exterieur : interdire les protocoles de news, forums ..."priority="2"serv_inv="0"service="gr_forum"src_inv="0"tag="Interdiction des forums">
<sourcename="admin"/>
<destinationname="exterieur"/>
</directive>
<directiveaccept="0"action="1"attrs="1"dest_inv="0"ipsec="0"libelle="Interdire les connexions FTP"priority="3"serv_inv="0"service="gr_ftp"src_inv="0"tag="Interdire les connexions FTP">
<sourcename="admin"/>
<destinationname="exterieur"/>
</directive>
<directiveaccept="0"action="1"attrs="1"dest_inv="0"ipsec="0"libelle="admin -> exterieur : interdire les protocoles de discussion en ligne (irc ...)"priority="4"serv_inv="0"service="gr_irc"src_inv="0"tag="Interdire l'utilisation des dialogues en direct">
<sourcename="admin"/>
<destinationname="exterieur"/>
</directive>
<directiveaccept="0"action="1"attrs="1"dest_inv="0"ipsec="0"libelle="admin -> exterieur : interdire les protocoles de messagerie (pop, imap ...)"priority="5"serv_inv="0"service="gr_messagerie"src_inv="0"tag="Interdiction des protocoles de messagerie">
<sourcename="admin"/>
<destinationname="exterieur"/>
</directive>
<!--
<directive accept="0" action="1" attrs="1" dest_inv="0" ipsec="0" libelle="admin -> exterieur : tout interdire (sauf le web via le proxy)" priority="6" serv_inv="0" service="gr_restreint" src_inv="0" tag="Internet restreint">
<source name="admin" />
<destination name="exterieur" />
</directive>
<directive accept="0" action="4" attrs="17" dest_inv="0" ipsec="0" libelle="Redirection des flux http avec proxy alternatif" nat_port="3128" priority="7" serv_inv="0" service="gr_redirection_proxy" src_inv="0" tag="ProxyBypass1">
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="ssh admin vers Amon"priority="1"serv_inv="0"service="ssh"src_inv="0"tag="SSHDepuiseth2">
<sourcename="admin_ssh"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="administration admin vers Amon"priority="2"serv_inv="0"service="admin_amon"src_inv="0"tag="AdminDepuiseth2">
<sourcename="admin_admin"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="administration admin vers Amon"priority="3"serv_inv="0"service="lightsquid"src_inv="0"tag="lightsquid1">
<sourcename="admin_admin"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="pas de description"priority="4"serv_inv="0"service="dns-tcp"src_inv="0">
<sourcename="admin"/>
<destinationname="internet_eth2"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="pas de description"priority="5"serv_inv="0"service="dns-udp"src_inv="0">
<sourcename="admin"/>
<destinationname="internet_eth2"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="autoriser l'acces a Nuauth"priority="6"serv_inv="0"service="nuauth"src_inv="0"tag="auth_nufw">
<sourcename="admin"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="7"serv_inv="0"service="eole-sso"src_inv="0"tag="eole_sso">
<sourcename="admin"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="pas de description"priority="8"serv_inv="0"service="proxy"src_inv="0">
<sourcename="admin"/>
<destinationname="internet_eth2"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="9"serv_inv="0"service="proxy2"src_inv="0"tag="Activer squid2">
<sourcename="admin"/>
<destinationname="internet_eth2"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="10"serv_inv="0"service="cntlm"src_inv="0"tag="cntlm">
<sourcename="admin"/>
<destinationname="internet_eth2"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="gen_config admin vers Amon"priority="11"serv_inv="0"service="gen_config"src_inv="0"tag="SSHDepuiseth2">
<sourcename="admin_ssh"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="Acces backend EAD admin vers Amon"priority="12"serv_inv="0"service="ead_server"src_inv="0"tag="BackendEADDepuiseth2">
<sourcename="admin_backend_ead"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="raduis admin vers Amon"priority="13"serv_inv="0"service="gr_radius"src_inv="0"tag="ActiverRadiuseth2">
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="Autoriser ntp depuis admin"priority="15"serv_inv="0"service="ntp"src_inv="0">
<sourcename="admin"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="16"serv_inv="0"service="ldap"src_inv="0"tag="activer_ldap">
<sourcename="admin"/>
<destinationname="bdd"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="17"serv_inv="0"service="ldaps"src_inv="0"tag="activer_ldaps">
<sourcename="admin"/>
<destinationname="bdd"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="interface web sympa"priority="18"serv_inv="0"service="sympa-internet"src_inv="0"tag="AdminDepuiseth2">
<sourcename="admin_admin"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="interface web sympa"priority="19"serv_inv="0"service="sympa-restreint"src_inv="0">
<sourcename="admin"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="Activer NFS depuis les clients"priority="20"serv_inv="0"service="nfs"src_inv="0"tag="activer_nfs">
<sourcename="client_nfs"/>
<destinationname="bastion"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="21"serv_inv="0"service="imap"src_inv="0"tag="activer_courrier_imap">
<sourcename="admin"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="22"serv_inv="0"service="imap4-ssl"src_inv="0"tag="activer_courrier_imap">
<sourcename="admin"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="23"serv_inv="0"service="pop"src_inv="0"tag="activer_courrier_pop">
<sourcename="admin"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="24"serv_inv="0"service="pop3s"src_inv="0"tag="activer_courrier_pop">
<sourcename="admin"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="pas de description"priority="25"serv_inv="0"service="smtp"src_inv="0">
<sourcename="admin"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="pas de description"priority="26"serv_inv="0"service="smtps"src_inv="0">
<sourcename="admin"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="27"serv_inv="0"service="xmpp"src_inv="0"tag="activer_xmpp">
<sourcename="admin"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="28"serv_inv="0"service="xmpp-ssl"src_inv="0"tag="activer_xmpp">
<sourcename="admin"/>
<destinationname="reseau"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="pas de description"priority="29"serv_inv="0"service="tftpd-hpa"src_inv="0"tag="activer_tftp">
<sourcename="admin"/>
<destinationname="bdd"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="interface web CUPS"priority="30"serv_inv="0"service="cups"src_inv="0"tag="activer_cups1">
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="Autorise le ping vers le conteneur"priority="35"serv_inv="0"service="echo-request"src_inv="0">
<sourcename="admin"/>
<destinationname="partage_eth2"/>
</directive>
<directiveaccept="0"action="2"attrs="0"dest_inv="0"ipsec="0"libelle="Autorise le ping vers le conteneur"priority="36"serv_inv="0"service="echo-request"src_inv="0">
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="Open Eclair ports on AmonEcole"priority="38"serv_inv="0"service="amonecole-eclair"src_inv="0"tag="activer_eclair_amonecole">
<sourcename="admin"/>
<destinationname="ltspserver_eth0"/>
</directive>
<directiveaccept="0"action="2"attrs="17"dest_inv="0"ipsec="0"libelle="Open Gaspacho and TFTPD for Eclair on AmonEcole"priority="39"serv_inv="0"service="amonecole-eclair-partage"src_inv="0"tag="activer_eclair_amonecole">