From dc1f5c7d6c0ebec9d6ed01ef7cf606268fa73918 Mon Sep 17 00:00:00 2001 From: David Beniamine <david.beniamine@tetras-libre.fr> Date: Fri, 15 Feb 2019 12:32:04 +0100 Subject: [PATCH] WIP era file for 3zones dmz --- eole/era/3zones-dmz-cuques.xml | 68 ++++++++++++++++++++++++++++++++++ 1 file changed, 68 insertions(+) create mode 100644 eole/era/3zones-dmz-cuques.xml diff --git a/eole/era/3zones-dmz-cuques.xml b/eole/era/3zones-dmz-cuques.xml new file mode 100644 index 0000000..04170bb --- /dev/null +++ b/eole/era/3zones-dmz-cuques.xml @@ -0,0 +1,68 @@ +<?xml version="1.0" encoding="UTF-8" ?> + +<firewall name="/usr/share/era/modeles/3zones-dmz-cuques.xml" model="/usr/share/era/modeles/3zones-dmz.xml" version="2.42"> + <zones> + </zones> + <include> + + </include> + <services> + <service name="apt-cacher-ng" protocol="tcp" ports="3142" id="82" libelle="apt cacher" tcpwrapper=""/> + <service name="registry" protocol="tcp" ports="9998" id="83" libelle="registry" tcpwrapper=""/> + </services> + <qosclasses upload="" download=""> + </qosclasses> + <extremites> + </extremites> + <ranges> + </ranges> + <user_groups> + </user_groups> + <applications> + </applications> + <flux-list> + <flux zoneA="bastion" zoneB="exterieur"> + <montantes default_policy="0"> + </montantes> + <descendantes default_policy="1"> + </descendantes> + </flux> + <flux zoneA="exterieur" zoneB="pedago"> + <montantes default_policy="0"> + </montantes> + <descendantes default_policy="1"> + </descendantes> + </flux> + <flux zoneA="bastion" zoneB="pedago"> + <montantes default_policy="0"> + <directive service="registry" priority="41" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0"> + <source name="pedago"/> + <destination name="partage_eth1"/> + </directive> + </montantes> + <descendantes default_policy="1"> + </descendantes> + </flux> + <flux zoneA="bastion" zoneB="pedago"> + <montantes default_policy="0"> + <directive service="cups" priority="42" action="2" attrs="0" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0"> + <source name="pedago"/> + <destination name="partage_eth1"/> + </directive> + </montantes> + <descendantes default_policy="1"> + </descendantes> + </flux> + + <flux zoneA="bastion" zoneB="pedago"> + <montantes default_policy="0"> + <directive service="apt-cacher-ng" priority="40" action="2" attrs="0" mark_operator="None" mark_value="" src_inv="0" dest_inv="0" serv_inv="0" libelle="pas de description" ipsec="0" accept="0"> + <source name="pedago"/> + <destination name="bastion"/> + </directive> + </montantes> + <descendantes default_policy="1"> + </descendantes> + </flux> + </flux-list> +</firewall> -- GitLab