C'est un peu long mais j'ai tout mis ...
Je comptais mettre des regles avec FWBUILDER mais j'ai pas eu le temps et de tt facon ca marche plus alors !!
Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
77 9951 ACCEPT all -- lo any anywhere anywhere
0 0 DROP !icmp -- any any anywhere anywhere state INVALID
0 0 eth1_in all -- eth1 any anywhere anywhere
0 0 eth0_in all -- eth0 any anywhere anywhere
0 0 Reject all -- any any anywhere anywhere
0 0 LOG all -- any any anywhere anywhere LOG level info prefix `Shorewall:INPUT:REJECT:'
0 0 reject all -- any any anywhere anywhere
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 DROP !icmp -- any any anywhere anywhere state INVALID
0 0 eth1_fwd all -- eth1 any anywhere anywhere
0 0 eth0_fwd all -- eth0 any anywhere anywhere
0 0 Reject all -- any any anywhere anywhere
0 0 LOG all -- any any anywhere anywhere LOG level info prefix `Shorewall:FORWARD:REJECT:'
0 0 reject all -- any any anywhere anywhere
Chain OUTPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
77 9951 ACCEPT all -- any lo anywhere anywhere
0 0 DROP !icmp -- any any anywhere anywhere state INVALID
0 0 fw2net all -- any eth1 anywhere anywhere
53 3888 all2all all -- any eth0 anywhere anywhere
0 0 Reject all -- any any anywhere anywhere
0 0 LOG all -- any any anywhere anywhere
LOG level info prefix `Shorewall:OUTPUT:REJECT:'
0 0 reject all -- any any anywhere anywhere
Chain Drop (1 references)
pkts bytes target prot opt in out source destination
0 0 RejectAuth all -- any any anywhere anywhere
0 0 dropBcast all -- any any anywhere anywhere
0 0 DropSMB all -- any any anywhere anywhere
0 0 DropUPnP all -- any any anywhere anywhere
0 0 dropNonSyn all -- any any anywhere anywhere
0 0 DropDNSrep all -- any any anywhere anywhere
Chain DropDNSrep (2 references)
pkts bytes target prot opt in out source destination
0 0 DROP udp -- any any anywhere anywhere udp spt:domain
Chain DropSMB (1 references)
pkts bytes target prot opt in out source destination
0 0 DROP udp -- any any anywhere anywhere udp dpt:135
0 0 DROP udp -- any any anywhere anywhere udp dpts:netbios-ns:netbios-ssn
0 0 DROP udp -- any any anywhere anywhere udp dpt:microsoft-ds
0 0 DROP tcp -- any any anywhere anywhere tcp dpt:135
0 0 DROP tcp -- any any anywhere anywhere tcp dpt:netbios-ssn
0 0 DROP tcp -- any any anywhere anywhere tcp dpt:microsoft-ds
Chain DropUPnP (2 references)
pkts bytes target prot opt in out source destination
0 0 DROP udp -- any any anywhere anywhere udp dpt:1900
Chain Reject (4 references)
pkts bytes target prot opt in out source destination
53 3888 RejectAuth all -- any any anywhere anywhere
53 3888 dropBcast all -- any any anywhere anywhere
53 3888 RejectSMB all -- any any anywhere anywhere
48 3408 DropUPnP all -- any any anywhere anywhere
48 3408 dropNonSyn all -- any any anywhere anywhere
48 3408 DropDNSrep all -- any any anywhere anywhere
Chain RejectAuth (2 references)
pkts bytes target prot opt in out source destination
0 0 reject tcp -- any any anywhere anywhere tcp dpt:auth
Chain RejectSMB (1 references)
pkts bytes target prot opt in out source destination
0 0 reject udp -- any any anywhere anywhere udp dpt:135
5 480 reject udp -- any any anywhere anywhere udp dpts:netbios-ns:netbios-ssn
0 0 reject udp -- any any anywhere anywhere udp dpt:microsoft-ds
0 0 reject tcp -- any any anywhere anywhere tcp dpt:135
0 0 reject tcp -- any any anywhere anywhere tcp dpt:netbios-ssn
0 0 reject tcp -- any any anywhere anywhere tcp dpt:microsoft-ds
Chain all2all (2 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- any any anywhere anywhere state RELATED,ESTABLISHED
53 3888 Reject all -- any any anywhere anywhere
48 3408 LOG all -- any any anywhere anywhere LOG level info prefix `Shorewall:all2all:REJECT:'
48 3408 reject all -- any any anywhere anywhere
Chain dropBcast (2 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- any any anywhere anywhere PKTTYPE = broadcast
0 0 DROP all -- any any anywhere anywhere PKTTYPE = multicast
Chain dropNonSyn (2 references)
pkts bytes target prot opt in out source destination
0 0 DROP tcp -- any any anywhere anywhere tcp flags:!SYN,RST,ACK/SYN
Chain dynamic (4 references)
pkts bytes target prot opt in out source destination
Chain eth0_fwd (1 references)
pkts bytes target prot opt in out source destination
0 0 dynamic all -- any any anywhere anywhere
state NEW
0 0 loc2net all -- any eth1 anywhere anywhere
Chain eth0_in (1 references)
pkts bytes target prot opt in out source destination
0 0 dynamic all -- any any anywhere anywhere state NEW
0 0 all2all all -- any any anywhere anywhere
Chain eth1_fwd (1 references)
pkts bytes target prot opt in out source destination
0 0 dynamic all -- any any anywhere anywhere state NEW
0 0 net2all all -- any eth0 anywhere anywhere
Chain eth1_in (1 references)
pkts bytes target prot opt in out source destination
0 0 dynamic all -- any any anywhere anywhere state NEW
0 0 net2all all -- any any anywhere anywhere
Chain fw2net (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- any any anywhere anywhere state RELATED,ESTABLISHED
0 0 ACCEPT all -- any any anywhere anywhere
Chain icmpdef (0 references)
pkts bytes target prot opt in out source destination
Chain loc2net (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- any any anywhere anywhere state RELATED,ESTABLISHED
0 0 ACCEPT all -- any any anywhere anywhere
Chain net2all (2 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- any any anywhere anywhere state RELATED,ESTABLISHED
0 0 Drop all -- any any anywhere anywhere
0 0 LOG all -- any any anywhere anywhere LOG level info prefix `Shorewall:net2all:DROP:'
0 0 DROP all -- any any anywhere anywhere
Chain reject (11 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- any any anywhere anywhere PKTTYPE = broadcast
0 0 DROP all -- any any anywhere anywhere PKTTYPE = multicast
0 0 DROP all -- any any 255.255.255.255 anywhere
0 0 DROP all -- any any 224.0.0.0/4 anywhere
0 0 REJECT tcp -- any any anywhere anywhere reject-with tcp-reset
53 3888 REJECT udp -- any any anywhere anywhere reject-with icmp-port-unreachable
0 0 REJECT icmp -- any any anywhere anywhere reject-with icmp-host-unreachable
0 0 REJECT all -- any any anywhere anywhere reject-with icmp-host-prohibited
Chain shorewall (0 references)
pkts bytes target prot opt in out source destination
Chain smurfs (0 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- any any 255.255.255.255 anywhere LOG level info prefix `Shorewall:smurfs:DROP:'
0 0 DROP all -- any any 255.255.255.255 anywhere
0 0 LOG all -- any any 224.0.0.0/4 anywhere LOG level info prefix `Shorewall:smurfs:DROP:'
0 0 DROP all -- any any 224.0.0.0/4 anywhere