[Qa-jenkins-scm] [jenkins.debian.net] 02/06: update shorewall6.conf, to the stretch version, retaining most local changes

Mattia Rizzolo mattia at debian.org
Sat Apr 7 11:46:21 UTC 2018


This is an automated email from the git hooks/post-receive script.

mattia pushed a commit to branch master
in repository jenkins.debian.net.

commit 1454f4806b3c1a4961fe34c7c1908113138b5d2a
Author: Mattia Rizzolo <mattia at debian.org>
Date:   Sat Apr 7 13:37:11 2018 +0200

    update shorewall6.conf, to the stretch version, retaining most local changes
    
    Signed-off-by: Mattia Rizzolo <mattia at debian.org>
---
 TODO4stretch-host-upgrades.txt               |   1 -
 hosts/jenkins/etc/shorewall6/shorewall6.conf | 110 +++++++++++++++++++++------
 2 files changed, 86 insertions(+), 25 deletions(-)

diff --git a/TODO4stretch-host-upgrades.txt b/TODO4stretch-host-upgrades.txt
index 63a330a..54d3cf7 100644
--- a/TODO4stretch-host-upgrades.txt
+++ b/TODO4stretch-host-upgrades.txt
@@ -2,7 +2,6 @@ things to look at on jenkins.d.n. after the upgrade
 ---------------------------------------------------
 kept the jessie versions:
 	Configuration file '/etc/default/shorewall'
-	Configuration file '/etc/shorewall6/shorewall6.conf'
 	Configuration file '/etc/apache2/conf-available/security.conf'
 
 
diff --git a/hosts/jenkins/etc/shorewall6/shorewall6.conf b/hosts/jenkins/etc/shorewall6/shorewall6.conf
index a2f75cf..1a54266 100644
--- a/hosts/jenkins/etc/shorewall6/shorewall6.conf
+++ b/hosts/jenkins/etc/shorewall6/shorewall6.conf
@@ -1,6 +1,6 @@
 ###############################################################################
 #
-#  Shorewall Version 4 -- /etc/shorewall6/shorewall6.conf
+#  Shorewall Version 5 -- /etc/shorewall6/shorewall6.conf
 #
 #  For information about the settings in this file, type "man shorewall6.conf"
 #
@@ -13,22 +13,38 @@
 STARTUP_ENABLED=Yes
 
 ###############################################################################
-#		              V E R B O S I T Y
+#			     V E R B O S I T Y
 ###############################################################################
 
 VERBOSITY=1
 
 ###############################################################################
+#			        P A G E R
+###############################################################################
+
+PAGER=
+
+###############################################################################
+#			     F I R E W A L L
+###############################################################################
+
+FIREWALL=
+
+###############################################################################
 #			       L O G G I N G
 ###############################################################################
 
-BLACKLIST_LOGLEVEL=
+BLACKLIST_LOG_LEVEL=
+
+INVALID_LOG_LEVEL=
+
+LOG_BACKEND=
 
 LOG_VERBOSITY=2
 
 LOGALLNEW=
 
-LOGFILE=
+LOGFILE=/var/log/messages
 
 LOGFORMAT="Shorewall:%s:%s:"
 
@@ -40,6 +56,8 @@ MACLIST_LOG_LEVEL=info
 
 RELATED_LOG_LEVEL=
 
+RPFILTER_LOG_LEVEL=info
+
 SFILTER_LOG_LEVEL=info
 
 SMURF_LOG_LEVEL=info
@@ -48,11 +66,13 @@ STARTUP_LOG=/var/log/shorewall6-init.log
 
 TCP_FLAGS_LOG_LEVEL=info
 
+UNTRACKED_LOG_LEVEL=
+
 ###############################################################################
 #	L O C A T I O N	  O F	F I L E S   A N D   D I R E C T O R I E S
 ###############################################################################
 
-CONFIG_PATH=${CONFDIR}/shorewall6:${SHAREDIR}/shorewall6:${SHAREDIR}/shorewall
+CONFIG_PATH="${CONFDIR}/shorewall6:/usr/share/shorewall6:${SHAREDIR}/shorewall"
 
 GEOIPDIR=/usr/share/xt_geoip/LE
 
@@ -66,15 +86,17 @@ LOCKFILE=
 
 MODULESDIR=
 
+NFACCT=
+
 PERL=/usr/bin/perl
 
-PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin:/usr/local/sbin
+PATH="/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin:/usr/local/sbin"
 
-RESTOREFILE=
+RESTOREFILE=restore6
 
 SHOREWALL_SHELL=/bin/sh
 
-SUBSYSLOCK=
+SUBSYSLOCK=""
 
 TC=
 
@@ -82,14 +104,14 @@ TC=
 #		D E F A U L T   A C T I O N S / M A C R O S
 ###############################################################################
 
-ACCEPT_DEFAULT="none"
-DROP_DEFAULT="Drop"
-NFQUEUE_DEFAULT="none"
-QUEUE_DEFAULT="none"
-REJECT_DEFAULT="Reject"
+ACCEPT_DEFAULT=none
+DROP_DEFAULT=Drop
+NFQUEUE_DEFAULT=none
+QUEUE_DEFAULT=none
+REJECT_DEFAULT=Reject
 
 ###############################################################################
-#                        R S H / R C P  C O M M A N D S
+#			 R S H / R C P	C O M M A N D S
 ###############################################################################
 
 RCP_COMMAND='scp ${files} ${root}@${system}:${destination}'
@@ -105,42 +127,54 @@ ACCOUNTING_TABLE=filter
 
 ADMINISABSENTMINDED=Yes
 
-AUTO_COMMENT=Yes
+AUTOCOMMENT=Yes
+
+AUTOHELPERS=Yes
 
 AUTOMAKE=No
 
-BLACKLISTNEWONLY=Yes
+BASIC_FILTERS=No
+
+BLACKLIST="NEW,INVALID,UNTRACKED"
+
+CHAIN_SCRIPTS=Yes
 
 CLAMPMSS=No
 
-CLEAR_TC=Yes
+CLEAR_TC=No
 
 COMPLETE=No
 
+DEFER_DNS_RESOLUTION=Yes
+
 DELETE_THEN_ADD=Yes
 
 DONT_LOAD=
 
 DYNAMIC_BLACKLIST=Yes
 
-EXPAND_POLICIES=No
+EXPAND_POLICIES=Yes
 
 EXPORTMODULES=Yes
 
 FASTACCEPT=No
 
-FORWARD_CLEAR_MARK=
+FORWARD_CLEAR_MARK=Yes
+
+HELPERS=
+
+IGNOREUNKNOWNVARIABLES=No
 
 IMPLICIT_CONTINUE=No
 
+INLINE_MATCHES=No
+
 IPSET_WARNINGS=Yes
 
-IP_FORWARDING=Off
+IP_FORWARDING=keep
 
 KEEP_RT_TABLES=Yes
 
-LEGACY_FASTSTART=No
-
 LOAD_HELPERS_ONLY=Yes
 
 MACLIST_TABLE=filter
@@ -159,8 +193,16 @@ OPTIMIZE=1
 
 OPTIMIZE_ACCOUNTING=No
 
+REJECT_ACTION=
+
 REQUIRE_INTERFACE=No
 
+RESTART=restart
+
+RESTORE_ROUTEMARKS=Yes
+
+SAVE_IPSETS=No
+
 TC_ENABLED=No
 
 TC_EXPERT=No
@@ -169,11 +211,23 @@ TC_PRIOMAP="2 3 3 3 2 3 1 1 2 2 2 2 2 2 2 2"
 
 TRACK_PROVIDERS=Yes
 
-USE_DEFAULT_RT=No
+TRACK_RULES=No
+
+USE_DEFAULT_RT=Yes
 
 USE_PHYSICAL_NAMES=No
 
-ZONE2ZONE=2
+USE_RT_NAMES=No
+
+VERBOSE_MESSAGES=Yes
+
+WARNOLDCAPVERSION=Yes
+
+WORKAROUNDS=No
+
+ZERO_MARKS=No
+
+ZONE2ZONE=-
 
 ###############################################################################
 #			P A C K E T   D I S P O S I T I O N
@@ -181,16 +235,22 @@ ZONE2ZONE=2
 
 BLACKLIST_DISPOSITION=DROP
 
+INVALID_DISPOSITION=CONTINUE
+
 MACLIST_DISPOSITION=REJECT
 
 RELATED_DISPOSITION=ACCEPT
 
 SFILTER_DISPOSITION=DROP
 
+RPFILTER_DISPOSITION=DROP
+
 SMURF_DISPOSITION=DROP
 
 TCP_FLAGS_DISPOSITION=DROP
 
+UNTRACKED_DISPOSITION=CONTINUE
+
 ################################################################################
 #			P A C K E T  M A R K  L A Y O U T
 ################################################################################
@@ -204,3 +264,5 @@ PROVIDER_OFFSET=
 MASK_BITS=
 
 ZONE_BITS=0
+
+#LAST LINE -- DO NOT REMOVE

-- 
Alioth's /usr/local/bin/git-commit-notice on /srv/git.debian.org/git/qa/jenkins.debian.net.git



More information about the Qa-jenkins-scm mailing list