bah, j'ai trouvé
j'ai tracé shorewall et j'ai commenté dans /usr/share/shorewall/firewall
setpolicy OUTPUT DROP setpolicy INPUT DROP |
dans la fonction initialize_netfilter ()
peu après
echo "Deleting user chains..."
exists_INPUT=Yes
exists_OUTPUT=Yes
exists_FORWARD=Yes
process_criticalhosts
if [ -n "$CRITICALHOSTS" ]; then
setpolicy INPUT ACCEPT
setpolicy OUTPUT ACCEPT
setpolicy FORWARD DROP
deleteallchains
enable_critical_hosts
# setpolicy INPUT DROP
# setpolicy OUTPUT DROP
[ -n "$CLAMPMSS" ] && setup_mss
setcontinue FORWARD
setcontinue INPUT
setcontinue OUTPUT
else
# setpolicy OUTPUT DROP
# setpolicy INPUT DROP
setpolicy FORWARD DROP
deleteallchains
faut aussi commenter ça dans la fontion stop_firewall()
# for chain in INPUT OUTPUT FORWARD; do
# setpolicy $chain DROP
# done
#
# deleteallchains
# else
# for chain in INPUT FORWARD; do
# setpolicy $chain DROP
# done
#
# setpolicy OUTPUT ACCEPT
#
deleteallchains
#
# for chain in INPUT FORWARD; do
# setcontinue $chain
# done
C'est grave docteur ?
Message édité par depx le 12-08-2006 à 00:27:37