#
# Shorewall version 4.0 - Sample Rules File for one-interface configuration.
# Copyright (C) 2006 by the Shorewall Team
#
# This library is free software; you can redistribute it and/or
# modify it under the terms of the GNU Lesser General Public
# License as published by the Free Software Foundation; either
# version 2.1 of the License, or (at your option) any later version.
#
# See the file README.txt for further details.
#------------------------------------------------------------------------------------------------------------
# For information on entries in this file, type "man shorewall-rules"
######################################################################################################################################################################################################
#ACTION		SOURCE		DEST		PROTO	DEST	SOURCE		ORIGINAL	RATE		USER/	MARK	CONNLIMIT	TIME		HEADERS		SWITCH		HELPER
#							PORT	PORT(S)		DEST		LIMIT		GROUP
#SECTION ALL
#SECTION ESTABLISHED
#SECTION RELATED

SECTION INVALID

?COMMENT Drop invalid packets generated by weather applet
Invalid(DROP)	$FW			net:98.137.200.255	tcp
Invalid(DROP)	net:98.137.200.255	$FW			tcp
?COMMENT
#?COMMENT test weather 
#Invalid(DROP)	$FW			net:98.137.100.255	tcp
#Invalid(DROP)	net:98.137.100.255	$FW			tcp
#?COMMENT

#SECTION UNTRACKED
SECTION NEW

# Drop packets in the INVALID state

Invalid(DROP)  	net    	        $FW		tcp

# Permit all ICMP traffic FROM local
ACCEPT		loc		$FW		icmp

# Drop Ping from the "bad" net zone.. and prevent your log from being flooded..

Ping(DROP)	net		$FW

# Permit all ICMP traffic FROM the firewall TO the net zone

ACCEPT		$FW		net		icmp

?COMMENT Accept SSH connections from local network
SSH(ACCEPT):$LOG	loc		$FW
?COMMENT

?COMMENT Restrict network access to allowed accounts only
ACCEPT		$FW		all		{ user=hwerner,root,ntp:ntp }
?COMMENT

