Salut Pascalhambourg,sur ubuntu avec gnome le démarrage doit ce faire à la main
(un bug ??)avec la dernière version 1.0.3. dans la doc d’ubuntu ont doit le faire nous même le “/etc/init.d/firestarter” mais dans mon cas iptables me bloque la console bash (pb de sudoers ??)donc j’avais pensé utiliser le retour de iptables -L
faire un fichier /etc/init.d/firestarter qui me lancerait cette config :
root@tosh8:/home/jpr# iptables -L
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT tcp – dns1m11.airtel.es anywhere tcp flags:!FIN,SYN,RST,ACK/SYN
ACCEPT udp – dns1m11.airtel.es anywhere
ACCEPT tcp – dns2b11.airtel.es anywhere tcp flags:!FIN,SYN,RST,ACK/SYN
ACCEPT udp – dns2b11.airtel.es anywhere
ACCEPT all – anywhere anywhere
LSI udp – anywhere anywhere udp dpt:33434
LSI icmp – anywhere anywhere
DROP all – anywhere 255.255.255.255
DROP all – BASE-ADDRESS.MCAST.NET/8 anywhere
DROP all – anywhere BASE-ADDRESS.MCAST.NET/8
DROP all – 255.255.255.255 anywhere
DROP all – anywhere 0.0.0.0
DROP all – anywhere anywhere state INVALID
LSI all -f anywhere anywhere limit: avg 10/min burst 5
INBOUND all – anywhere anywhere
LOG_FILTER all – anywhere anywhere
LOG all – anywhere anywhere LOG level info prefix `Unknown Input’
Chain FORWARD (policy DROP)
target prot opt source destination
LSI udp – anywhere anywhere udp dpt:33434
LSI icmp – anywhere anywhere
LOG_FILTER all – anywhere anywhere
LOG all – anywhere anywhere LOG level info prefix `Unknown Forward’
Chain OUTPUT (policy DROP)
target prot opt source destination
ACCEPT tcp – 77.208.90.208 dns1m11.airtel.es tcp dpt:domain
ACCEPT udp – 77.208.90.208 dns1m11.airtel.es udp dpt:domain
ACCEPT tcp – 77.208.90.208 dns2b11.airtel.es tcp dpt:domain
ACCEPT udp – 77.208.90.208 dns2b11.airtel.es udp dpt:domain
ACCEPT all – anywhere anywhere
DROP all – BASE-ADDRESS.MCAST.NET/8 anywhere
DROP all – anywhere BASE-ADDRESS.MCAST.NET/8
DROP all – 255.255.255.255 anywhere
DROP all – anywhere 0.0.0.0
DROP all – anywhere anywhere state INVALID
OUTBOUND all – anywhere anywhere
LOG_FILTER all – anywhere anywhere
LOG all – anywhere anywhere LOG level info prefix `Unknown Output’
Chain INBOUND (1 references)
target prot opt source destination
ACCEPT tcp – anywhere anywhere state RELATED,ESTABLISHED
ACCEPT udp – anywhere anywhere state RELATED,ESTABLISHED
LSI all – anywhere anywhere
Chain LOG_FILTER (5 references)
target prot opt source destination
Chain LSI (6 references)
target prot opt source destination
LOG_FILTER all – anywhere anywhere
LOG tcp – anywhere anywhere tcp flags:FIN,SYN,RST,ACK/SYN limit: avg 1/sec burst 5 LOG level info prefix Inbound ' DROP tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,ACK/SYN LOG tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,ACK/RST limit: avg 1/sec burst 5 LOG level info prefixInbound '
DROP tcp – anywhere anywhere tcp flags:FIN,SYN,RST,ACK/RST
LOG icmp – anywhere anywhere icmp echo-request limit: avg 1/sec burst 5 LOG level info prefix Inbound ' DROP icmp -- anywhere anywhere icmp echo-request LOG all -- anywhere anywhere limit: avg 5/sec burst 5 LOG level info prefixInbound '
DROP all – anywhere anywhere
Chain LSO (0 references)
target prot opt source destination
LOG_FILTER all – anywhere anywhere
LOG all – anywhere anywhere limit: avg 5/sec burst 5 LOG level info prefix `Outbound '
REJECT all – anywhere anywhere reject-with icmp-port-unreachable
Chain OUTBOUND (1 references)
target prot opt source destination
ACCEPT icmp – anywhere anywhere
ACCEPT tcp – anywhere anywhere state RELATED,ESTABLISHED
ACCEPT udp – anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all – anywhere anywhere
root@tosh8:/home/jpr#
root@tosh8:/home/jpr#