<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://mediawiki.netbreaker.de/mediawiki/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
		<id>http://mediawiki.netbreaker.de/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Ferm</id>
		<title>Ferm - Versionsgeschichte</title>
		<link rel="self" type="application/atom+xml" href="http://mediawiki.netbreaker.de/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Ferm"/>
		<link rel="alternate" type="text/html" href="http://mediawiki.netbreaker.de/mediawiki/index.php?title=Ferm&amp;action=history"/>
		<updated>2026-04-24T02:45:58Z</updated>
		<subtitle>Versionsgeschichte dieser Seite in ConfigWiki</subtitle>
		<generator>MediaWiki 1.19.20+dfsg-0+deb7u3</generator>

	<entry>
		<id>http://mediawiki.netbreaker.de/mediawiki/index.php?title=Ferm&amp;diff=434&amp;oldid=prev</id>
		<title>Netbreaker am 7. Januar 2011 um 16:07 Uhr</title>
		<link rel="alternate" type="text/html" href="http://mediawiki.netbreaker.de/mediawiki/index.php?title=Ferm&amp;diff=434&amp;oldid=prev"/>
				<updated>2011-01-07T16:07:10Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
			&lt;tr valign='top'&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Nächstältere Version&lt;/td&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Version vom 7. Januar 2011, 16:07 Uhr&lt;/td&gt;
			&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 14:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 14:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; mod state state (RELATED ESTABLISHED);&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; mod state state (RELATED ESTABLISHED);&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&amp;#160; &amp;#160; &amp;#160; &amp;#160; 	interface lo;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&amp;#160; &amp;#160; &amp;#160; &amp;#160; 	interface lo;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;	&amp;#160; &amp;#160; &amp;#160; &amp;#160; &lt;/del&gt;protocol (icmp esp ah);&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; 	&amp;#160; &amp;#160; &amp;#160; &amp;#160; &lt;/ins&gt;protocol (icmp esp ah);&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;	&amp;#160; &amp;#160; &amp;#160; &amp;#160; &lt;/del&gt;protocol udp dport 500;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; 	&amp;#160; &amp;#160; &amp;#160; &amp;#160; &lt;/ins&gt;protocol udp dport 500;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;		&lt;/del&gt;protocol tcp {&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; 		&lt;/ins&gt;protocol tcp {&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;		&amp;#160; &amp;#160; &lt;/del&gt;dport (http smtp);&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; 		&amp;#160; &amp;#160; &lt;/ins&gt;dport (http smtp);&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;		&amp;#160; &amp;#160; &lt;/del&gt;dport ssh mod hashlimit&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; 		&amp;#160; &amp;#160; &lt;/ins&gt;dport ssh mod hashlimit&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;		&amp;#160; &amp;#160; &lt;/del&gt;hashlimit 10/min&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; 		&amp;#160; &amp;#160; &lt;/ins&gt;hashlimit 10/min&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;		&amp;#160; &amp;#160; &lt;/del&gt;hashlimit-mode srcip&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; 		&amp;#160; &amp;#160; &lt;/ins&gt;hashlimit-mode srcip&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;		&amp;#160; &amp;#160; &lt;/del&gt;hashlimit-name ssh;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; 		&amp;#160; &amp;#160; &lt;/ins&gt;hashlimit-name ssh;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;		&lt;/del&gt;}&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; 		&lt;/ins&gt;}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; }&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; }&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; LOG log-prefix &amp;quot;reject-in &amp;quot;;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; &amp;#160; LOG log-prefix &amp;quot;reject-in &amp;quot;;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Netbreaker</name></author>	</entry>

	<entry>
		<id>http://mediawiki.netbreaker.de/mediawiki/index.php?title=Ferm&amp;diff=431&amp;oldid=prev</id>
		<title>Netbreaker: Die Seite wurde neu angelegt:  ~# aptitude install ferm  Beispielkonfiguration:  /etc/ferm# cat ferm.conf  # ferm rules generated by import-ferm  # http://ferm.foo-projects.org/  hook pre &quot;modprobe ...</title>
		<link rel="alternate" type="text/html" href="http://mediawiki.netbreaker.de/mediawiki/index.php?title=Ferm&amp;diff=431&amp;oldid=prev"/>
				<updated>2011-01-06T16:12:13Z</updated>
		
		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt:  ~# aptitude install ferm  Beispielkonfiguration:  /etc/ferm# cat ferm.conf  # ferm rules generated by import-ferm  # http://ferm.foo-projects.org/  hook pre &amp;quot;modprobe ...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt; ~# aptitude install ferm&lt;br /&gt;
&lt;br /&gt;
Beispielkonfiguration:&lt;br /&gt;
 /etc/ferm# cat ferm.conf&lt;br /&gt;
 # ferm rules generated by import-ferm&lt;br /&gt;
 # http://ferm.foo-projects.org/&lt;br /&gt;
 hook pre &amp;quot;modprobe nf_conntrack_ftp&amp;quot;;&lt;br /&gt;
 #hook pre &amp;quot;modprobe nf_nat_ftp&amp;quot;;&lt;br /&gt;
 domain ip {&lt;br /&gt;
    table filter {&lt;br /&gt;
        chain INPUT {&lt;br /&gt;
            policy DROP;&lt;br /&gt;
            ACCEPT {&lt;br /&gt;
                mod state state (RELATED ESTABLISHED);&lt;br /&gt;
        	interface lo;&lt;br /&gt;
	        protocol (icmp esp ah);&lt;br /&gt;
	        protocol udp dport 500;&lt;br /&gt;
		protocol tcp {&lt;br /&gt;
		    dport (http smtp);&lt;br /&gt;
		    dport ssh mod hashlimit&lt;br /&gt;
		    hashlimit 10/min&lt;br /&gt;
		    hashlimit-mode srcip&lt;br /&gt;
		    hashlimit-name ssh;&lt;br /&gt;
		}&lt;br /&gt;
            }&lt;br /&gt;
            LOG log-prefix &amp;quot;reject-in &amp;quot;;&lt;br /&gt;
            REJECT;&lt;br /&gt;
        }&lt;br /&gt;
        chain FORWARD { policy DROP; REJECT; }&lt;br /&gt;
        chain OUTPUT {&lt;br /&gt;
            policy DROP;&lt;br /&gt;
            ACCEPT {&lt;br /&gt;
                mod state state (RELATED ESTABLISHED);&lt;br /&gt;
        	outerface lo;&lt;br /&gt;
        	protocol udp dport domain daddr 192.168.4.100;&lt;br /&gt;
        	mod owner uid-owner (root rico);&lt;br /&gt;
            }&lt;br /&gt;
            LOG log-prefix reject-out;&lt;br /&gt;
            REJECT;&lt;br /&gt;
        }&lt;br /&gt;
    }&lt;br /&gt;
    table nat {&lt;br /&gt;
        chain POSTROUTING {&lt;br /&gt;
            policy ACCEPT;&lt;br /&gt;
            mod mark mark 0x25 MASQUERADE;&lt;br /&gt;
        }&lt;br /&gt;
        chain INPUT policy ACCEPT;&lt;br /&gt;
        chain OUTPUT policy ACCEPT;&lt;br /&gt;
        chain PREROUTING policy ACCEPT;&lt;br /&gt;
    }&lt;br /&gt;
    table mangle {&lt;br /&gt;
        chain OUTPUT {&lt;br /&gt;
            policy ACCEPT;&lt;br /&gt;
            protocol tcp dport 25 MARK set-xmark 0x25/0xffffffff;&lt;br /&gt;
        }&lt;br /&gt;
        chain FORWARD policy ACCEPT;&lt;br /&gt;
        chain INPUT policy ACCEPT;&lt;br /&gt;
        chain PREROUTING policy ACCEPT;&lt;br /&gt;
        chain POSTROUTING policy ACCEPT;&lt;br /&gt;
    }&lt;br /&gt;
 }&lt;/div&gt;</summary>
		<author><name>Netbreaker</name></author>	</entry>

	</feed>