From mboxrd@z Thu Jan 1 00:00:00 1970 From: Stefan Schantl To: development@lists.ipfire.org Subject: Re: [PATCH] suricata: Scan outgoing traffic, too Date: Tue, 29 Jan 2019 14:09:47 +0100 Message-ID: <8dd9fd1e81b22defe3857bf569b6aff1f2fea5c2.camel@ipfire.org> In-Reply-To: <1548763417-4998-1-git-send-email-michael.tremer@ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============4173316626781310017==" List-Id: --===============4173316626781310017== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Hello Michael, thanks for the patch - merged! Best regards, -Stefan > Connections from the firewall and through the proxy must be filtered, > too > > Signed-off-by: Michael Tremer > --- > src/initscripts/system/firewall | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/src/initscripts/system/firewall > b/src/initscripts/system/firewall > index 9a79cb1..a4fcee2 100644 > --- a/src/initscripts/system/firewall > +++ b/src/initscripts/system/firewall > @@ -189,6 +189,7 @@ iptables_init() { > iptables -N IPS > iptables -A INPUT -j IPS > iptables -A FORWARD -j IPS > + iptables -A OUTPUT -j IPS > > # Block non-established IPsec networks > iptables -N IPSECBLOCK --===============4173316626781310017== Content-Type: application/pgp-signature Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="signature.asc" MIME-Version: 1.0 LS0tLS1CRUdJTiBQR1AgU0lHTkFUVVJFLS0tLS0KCmlRSXpCQUFCQ2dBZEZpRUVXTzBOWHRTcnZo YXN5dERuVHRkT0ZZK1RzdDRGQWx4UVVKc0FDZ2tRVHRkT0ZZK1QKc3Q3N2FoQUF0ZWVuSlR6Yjgz Q21mTUp6a1RaNTNZSVRCZU4yZGV6bEd2Wm9pZGV2R2RlWm1Ta2hPeVhycFZYdwpESHlCZVFoa1JL M013WmNZVlcvRUd6b3VGWGl1OHNncmtDdVJNaXBsV3BGYUVBc0Q3ci9FaktjUjFiUDBIZ0M5Ckhh Q3VsazJpSGRkdGRJOW0vUzRiL3YvQ2Nwa1BOY0dTeXh2cjBqaDNzZWtNT0swUUN5cHNWR1l6Qnhp c1hjQlgKWWZqM2oySVgvdTVoYjduTzFTK2pDYm9JQWQxQmhDT2hFdllwZTRHVEdIUkVkOERlbjJW QllBYkxDeVJaTW15ZQpTc2krVk8ya2JGQTM0TDdFek5HZW1rb1dwdDFWMXQwOXUxaWI5ZTVlSHVU NW5rZ3dJeXBadE5ZRnFQMGxzQVJUCkNJYzJuS0M2VW9NcmZFZGYwMjZiNkl6c2xqRUFVUy9rV0NP R2dNdVVod2xqUElGejRpOXdFbTFIeVFrQnNoVkQKWUwrUVVJYnU3c3FaT0cweElQd2FMVkY2bEpW eGg3L283N2FjN2kyZHFsUlNTL3BodGtQM1hxb281dEtmUUpBVApHMlFSWDNKdUI5dkhJQjI1ZVll UWEySFlrdmJ0T0l5OFp6dFhLbU90Q1V5VzR4YkhtVTVJZlY4cTBodmc5WW9mCjEzSkV4NzN2Nldv RjVKZ09oaUtkZ2k0NCtiUWk0ZU1Qc05OWFExZHpjZ1BpWm03SVNKclhiMjBIZmdnK2xDOTMKV2lo QnpGNFhsNzVFaDg4M0lTYUwxZTdEcEQ1RlFUNitlZ2I4RHpDMHF1ZktJY2J6UUs2TTdhRktwamR6 RlFlMgp0ZklOVmYxM3d1Tno0a2g2c2pYTVVFeURiSEVXbHA4UStDMlJQWFI1dDhubVVBMjNhQUU9 Cj1RTVBoCi0tLS0tRU5EIFBHUCBTSUdOQVRVUkUtLS0tLQo= --===============4173316626781310017==--