Bryan C. Andregg <bandregg@redhat.com>
Jan Rkorajski <baggins@pld.org.pl> - converted to ipchains.

firewall-init HOWTO

I. What is it?

Firewall-init provides a SysV-init style start-up script and /etc/sysconfig
control over the available kernel IP packet filters  and accounting using
ipchains(8). In other words, instead of having to write your own script to be run
by init for firewalling or having to shove all of your rules in rc.local you can
use the handy configuration files provided.

II. What does it include?

The base package comes with the following files:
<file>					<description>
/etc/rc.d/init.d/firewall		-- initscript that starts/stops firewalling.
/etc/sysconfig/firewall			-- main control file.
/etc/sysconfig/firewall-rules		-- directory holding 'direction policy' files.
/usr/share/doc/firewall-init-*/README	-- this file.

III. /etc/rc.d/init.d/firewall

This script controls starting and stopping the firewall and must be called with
one option: start or stop. It runs prior to networking in start run-levels and
after networking in stop run-levels. First it checks whether or not firewalling
should be turned on in /etc/sysconfig/firewall and if yes sets default polices
from that files. Following that it sets any further policies as found in
/etc/sysconfig/firewall-rules/(input|output|forward).

IV. /etc/sysconfig/firewall

The format for this file is:

FIREWALL=(yes|no)
INPUT=(ACCEPT|DENY|REJECT)
OUTPUT=(ACCEPT|DENY|REJECT)
FORWARD=(ACCEPT|DENY|REJECT)
[MASQ_MODS=<list of modules to load>]

Where FIREWALL sets whether or not firewalling will be enabled and ACCOUNT sets
whether or not accounting is enabled. The other entries declare the default
policy for that rule-set. MASQ_MODS is intended to allow administrator load
kernel modules (ie. ip_masq_*) just after firewall setup is completed.

V. Firewalls: /etc/sysconfig/firewall-rules/(input|output|forward)

NOTE: blank lines and lines beginning with a '#' or ignored.
      lines may be continued by using the sh standard '\(newline)' form.

Each of the input, output or forward files takes the same specified form:

The format for each line is:
<policy> <protocol> <source_address>/<source_mask> <source_port(s)> \
         <dest_address>/<dest_mask> <dest_port(s)> <interface> <options>

policy:
	ACCEPT, DENY, REJECT, MASQ, REDIRECT, RETURN
protocol:
	all, icmp, tcp, udp
address/netmask:
	address part should be xxx.xxx.xxx.xxx, traditional notation.
	netmask part may be xxx.xxx.xxx.xxx, traditional notation.
	netmask part may be CIDR formatted, the number of ones in the network
	part of the address (255.255.255.0 = 24).
	To specify all hosts the netmask should be '0' and the address can be
	anything.
	Address may be preceeded by "!\ ", meaning "all addresses except
	specified". eg. !\ 127.0.0.1 = all except loopback.
ports:
	x, a single port
	x,y,z a list of individual ports
	x:z a range of ports
	A port listing for all ports may be give as 0:65535 or as the word
	'any'.
	Port may be preceeded by "!\ ", meaning "all ports except specified".
	eg. !\ www = all except port 80.
interface:
	name of an interface via which a packet is received, or via which is
	packet is going to be sent. When this option is set to 'any', the empty
	string is assumed, which has a special meaning and will match with
	any interface name. When the "!\ " argument is used before
	the interface name, the sense is inverted. If the interface name
	ends in a "+", then any interface which begins with this name will
	match.
options:
	any other ipchains(8) option that should be applied,
	for instance '-b', '-l' or '-t'. Also redirection port for REDIRECT.

VI. Example

The file input.example in this directory contains some minor examples.

VII. Masquerading

Masquerading an internal network through host is accomplished using the MASQ
destination in forward chain. So in order to masquerade  an internal
network of 192.168.0.0/24 (one of the private addresses), the following lines
should be placed in /etc/sysconfig/firewall-rules/forward:
--begin--

MASQ all 192.168.0.0/24 any 0/0 any any
DENY all 0/0 any 0/0 any any

--end--

VIII. Logging

Errors from ipchains(8) because of improper rules are logged to syslogd with a
priority of user.notice.
