Skip to content

Latest commit

 

History

History
788 lines (620 loc) · 21.5 KB

pve-firewall-macros.adoc

File metadata and controls

788 lines (620 loc) · 21.5 KB
'Amanda'

Amanda Backup

Action proto dport sport

PARAM

udp

10080

PARAM

tcp

10080

'Auth'

Auth (identd) traffic

Action proto dport sport

PARAM

tcp

113

'BGP'

Border Gateway Protocol traffic

Action proto dport sport

PARAM

tcp

179

'BitTorrent'

BitTorrent traffic for BitTorrent 3.1 and earlier

Action proto dport sport

PARAM

tcp

6881:6889

PARAM

udp

6881

'BitTorrent32'

BitTorrent traffic for BitTorrent 3.2 and later

Action proto dport sport

PARAM

tcp

6881:6999

PARAM

udp

6881

'CVS'

Concurrent Versions System pserver traffic

Action proto dport sport

PARAM

tcp

2401

'Ceph'

Ceph Storage Cluster traffic (Ceph Monitors, OSD & MDS Deamons)

Action proto dport sport

PARAM

tcp

6789

PARAM

tcp

6800:7300

'Citrix'

Citrix/ICA traffic (ICA, ICA Browser, CGP)

Action proto dport sport

PARAM

tcp

1494

PARAM

udp

1604

PARAM

tcp

2598

'DAAP'

Digital Audio Access Protocol traffic (iTunes, Rythmbox daemons)

Action proto dport sport

PARAM

tcp

3689

PARAM

udp

3689

'DCC'

Distributed Checksum Clearinghouse spam filtering mechanism

Action proto dport sport

PARAM

tcp

6277

'DHCPfwd'

Forwarded DHCP traffic

Action proto dport sport

PARAM

udp

67:68

67:68

'DHCPv6'

DHCPv6 traffic

Action proto dport sport

PARAM

udp

546:547

546:547

'DNS'

Domain Name System traffic (upd and tcp)

Action proto dport sport

PARAM

udp

53

PARAM

tcp

53

'Distcc'

Distributed Compiler service

Action proto dport sport

PARAM

tcp

3632

'FTP'

File Transfer Protocol

Action proto dport sport

PARAM

tcp

21

'Finger'

Finger protocol (RFC 742)

Action proto dport sport

PARAM

tcp

79

'GNUnet'

GNUnet secure peer-to-peer networking traffic

Action proto dport sport

PARAM

tcp

2086

PARAM

udp

2086

PARAM

tcp

1080

PARAM

udp

1080

'GRE'

Generic Routing Encapsulation tunneling protocol

Action proto dport sport

PARAM

47

'Git'

Git distributed revision control traffic

Action proto dport sport

PARAM

tcp

9418

'HKP'

OpenPGP HTTP keyserver protocol traffic

Action proto dport sport

PARAM

tcp

11371

'HTTP'

Hypertext Transfer Protocol (WWW)

Action proto dport sport

PARAM

tcp

80

'HTTPS'

Hypertext Transfer Protocol (WWW) over SSL

Action proto dport sport

PARAM

tcp

443

'ICPV2'

Internet Cache Protocol V2 (Squid) traffic

Action proto dport sport

PARAM

udp

3130

'ICQ'

AOL Instant Messenger traffic

Action proto dport sport

PARAM

tcp

5190

'IMAP'

Internet Message Access Protocol

Action proto dport sport

PARAM

tcp

143

'IMAPS'

Internet Message Access Protocol over SSL

Action proto dport sport

PARAM

tcp

993

'IPIP'

IPIP capsulation traffic

Action proto dport sport

PARAM

94

'IPsec'

IPsec traffic

Action proto dport sport

PARAM

udp

500

500

PARAM

50

'IPsecah'

IPsec authentication (AH) traffic

Action proto dport sport

PARAM

udp

500

500

PARAM

51

'IPsecnat'

IPsec traffic and Nat-Traversal

Action proto dport sport

PARAM

udp

500

PARAM

udp

4500

PARAM

50

'IRC'

Internet Relay Chat traffic

Action proto dport sport

PARAM

tcp

6667

'Jetdirect'

HP Jetdirect printing

Action proto dport sport

PARAM

tcp

9100

'L2TP'

Layer 2 Tunneling Protocol traffic

Action proto dport sport

PARAM

udp

1701

'LDAP'

Lightweight Directory Access Protocol traffic

Action proto dport sport

PARAM

tcp

389

'LDAPS'

Secure Lightweight Directory Access Protocol traffic

Action proto dport sport

PARAM

tcp

636

'MDNS'

Multicast DNS

Action proto dport sport

PARAM

udp

5353

'MSNP'

Microsoft Notification Protocol

Action proto dport sport

PARAM

tcp

1863

'MSSQL'

Microsoft SQL Server

Action proto dport sport

PARAM

tcp

1433

'Mail'

Mail traffic (SMTP, SMTPS, Submission)

Action proto dport sport

PARAM

tcp

25

PARAM

tcp

465

PARAM

tcp

587

'Munin'

Munin networked resource monitoring traffic

Action proto dport sport

PARAM

tcp

4949

'MySQL'

MySQL server

Action proto dport sport

PARAM

tcp

3306

'NNTP'

NNTP traffic (Usenet).

Action proto dport sport

PARAM

tcp

119

'NNTPS'

Encrypted NNTP traffic (Usenet)

Action proto dport sport

PARAM

tcp

563

'NTP'

Network Time Protocol (ntpd)

Action proto dport sport

PARAM

udp

123

'NeighborDiscovery'

IPv6 neighbor solicitation, neighbor and router advertisement

Action proto dport sport

PARAM

icmpv6

router-solicitation

PARAM

icmpv6

router-advertisement

PARAM

icmpv6

neighbor-solicitation

PARAM

icmpv6

neighbor-advertisement

'OSPF'

OSPF multicast traffic

Action proto dport sport

PARAM

89

'OpenVPN'

OpenVPN traffic

Action proto dport sport

PARAM

udp

1194

'PCA'

Symantec PCAnywere (tm)

Action proto dport sport

PARAM

udp

5632

PARAM

tcp

5631

'POP3'

POP3 traffic

Action proto dport sport

PARAM

tcp

110

'POP3S'

Encrypted POP3 traffic

Action proto dport sport

PARAM

tcp

995

'PPtP'

Point-to-Point Tunneling Protocol

Action proto dport sport

PARAM

47

PARAM

tcp

1723

'Ping'

ICMP echo request

Action proto dport sport

PARAM

icmp

echo-request

'PostgreSQL'

PostgreSQL server

Action proto dport sport

PARAM

tcp

5432

'Printer'

Line Printer protocol printing

Action proto dport sport

PARAM

tcp

515

'RDP'

Microsoft Remote Desktop Protocol traffic

Action proto dport sport

PARAM

tcp

3389

'RIP'

Routing Information Protocol (bidirectional)

Action proto dport sport

PARAM

udp

520

'RNDC'

BIND remote management protocol

Action proto dport sport

PARAM

tcp

953

'Razor'

Razor Antispam System

Action proto dport sport

PARAM

tcp

2703

'Rdate'

Remote time retrieval (rdate)

Action proto dport sport

PARAM

tcp

37

'Rsync'

Rsync server

Action proto dport sport

PARAM

tcp

873

'SANE'

SANE network scanning

Action proto dport sport

PARAM

tcp

6566

'SMB'

Microsoft SMB traffic

Action proto dport sport

PARAM

udp

135,445

PARAM

udp

137:139

PARAM

udp

1024:65535

137

PARAM

tcp

135,139,445

'SMBswat'

Samba Web Administration Tool

Action proto dport sport

PARAM

tcp

901

'SMTP'

Simple Mail Transfer Protocol

Action proto dport sport

PARAM

tcp

25

'SMTPS'

Encrypted Simple Mail Transfer Protocol

Action proto dport sport

PARAM

tcp

465

'SNMP'

Simple Network Management Protocol

Action proto dport sport

PARAM

udp

161:162

PARAM

tcp

161

'SPAMD'

Spam Assassin SPAMD traffic

Action proto dport sport

PARAM

tcp

783

'SSH'

Secure shell traffic

Action proto dport sport

PARAM

tcp

22

'SVN'

Subversion server (svnserve)

Action proto dport sport

PARAM

tcp

3690

'SixXS'

SixXS IPv6 Deployment and Tunnel Broker

Action proto dport sport

PARAM

tcp

3874

PARAM

udp

3740

PARAM

41

PARAM

udp

5072,8374

'Squid'

Squid web proxy traffic

Action proto dport sport

PARAM

tcp

3128

'Submission'

Mail message submission traffic

Action proto dport sport

PARAM

tcp

587

'Syslog'

Syslog protocol (RFC 5424) traffic

Action proto dport sport

PARAM

udp

514

PARAM

tcp

514

'TFTP'

Trivial File Transfer Protocol traffic

Action proto dport sport

PARAM

udp

69

'Telnet'

Telnet traffic

Action proto dport sport

PARAM

tcp

23

'Telnets'

Telnet over SSL

Action proto dport sport

PARAM

tcp

992

'Time'

RFC 868 Time protocol

Action proto dport sport

PARAM

tcp

37

'Trcrt'

Traceroute (for up to 30 hops) traffic

Action proto dport sport

PARAM

udp

33434:33524

PARAM

icmp

echo-request

'VNC'

VNC traffic for VNC display’s 0 - 99

Action proto dport sport

PARAM

tcp

5900:5999

'VNCL'

VNC traffic from Vncservers to Vncviewers in listen mode

Action proto dport sport

PARAM

tcp

5500

'Web'

WWW traffic (HTTP and HTTPS)

Action proto dport sport

PARAM

tcp

80

PARAM

tcp

443

'Webcache'

Web Cache/Proxy traffic (port 8080)

Action proto dport sport

PARAM

tcp

8080

'Webmin'

Webmin traffic

Action proto dport sport

PARAM

tcp

10000

'Whois'

Whois (nicname, RFC 3912) traffic

Action proto dport sport

PARAM

tcp

43