aboutsummaryrefslogtreecommitdiffstats
path: root/etc/webserver.net
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2015-11-20 16:50:29 -0500
committerLibravatar netblue30 <netblue30@yahoo.com>2015-11-20 16:50:29 -0500
commita039bce14d634e891a670202047b0be674e5d547 (patch)
treea6f11ab356bce247dcf80bc0231c5a694aa53a9e /etc/webserver.net
parenttesting (diff)
downloadfirejail-a039bce14d634e891a670202047b0be674e5d547.tar.gz
firejail-a039bce14d634e891a670202047b0be674e5d547.tar.zst
firejail-a039bce14d634e891a670202047b0be674e5d547.zip
added webserver.net and nolocal.net network filters
Diffstat (limited to 'etc/webserver.net')
-rw-r--r--etc/webserver.net30
1 files changed, 30 insertions, 0 deletions
diff --git a/etc/webserver.net b/etc/webserver.net
new file mode 100644
index 000000000..d165e6faf
--- /dev/null
+++ b/etc/webserver.net
@@ -0,0 +1,30 @@
1*filter
2:INPUT DROP [0:0]
3:FORWARD DROP [0:0]
4:OUTPUT DROP [0:0]
5
6###################################################################
7# Simple webserver filter
8#
9# Usage:
10# firejail --net=eth0 --ip=192.168.1.105 --netfilter=/etc/firejail/webserver.net /etc/init.d/apache2 start
11# firejail --net=eth0 --ip=192.168.1.105 --netfilter=/etc/firejail/webserver.net /etc/init.d/nginx start
12#
13###################################################################
14
15# allow webserver traffic
16-A INPUT -p tcp --dport 80 -m state --state NEW,ESTABLISHED -j ACCEPT
17-A OUTPUT -p tcp --sport 80 -m state --state ESTABLISHED -j ACCEPT
18-A INPUT -p tcp --dport 443 -m state --state NEW,ESTABLISHED -j ACCEPT
19-A OUTPUT -p tcp --sport 443 -m state --state ESTABLISHED -j ACCEPT
20
21# allow incoming ping
22-A INPUT -p icmp --icmp-type echo-request -j ACCEPT
23-A OUTPUT -p icmp --icmp-type echo-reply -j ACCEPT
24
25# allow outgoing DNS
26-A OUTPUT -p udp --dport 53 -j ACCEPT
27-A INPUT -p udp --sport 53 -j ACCEPT
28
29COMMIT
30