|
Packit |
292933 |
FWD_START_TEST([rich rule icmptypes with one family])
|
|
Packit |
292933 |
AT_KEYWORDS(rich icmp rhbz1855140)
|
|
Packit |
292933 |
|
|
Packit |
292933 |
FWD_CHECK([--permanent --zone public --add-rich-rule='rule icmp-type name="echo-request" accept'], 0, ignore)
|
|
Packit |
292933 |
FWD_CHECK([--permanent --zone public --add-rich-rule='rule icmp-type name="neighbour-advertisement" accept'], 0, ignore)
|
|
Packit |
292933 |
FWD_CHECK([--permanent --zone public --add-rich-rule='rule icmp-type name="timestamp-request" accept'], 0, ignore)
|
|
Packit |
292933 |
FWD_RELOAD
|
|
Packit |
292933 |
NFT_LIST_RULES([inet], [filter_IN_public_allow], 0, [dnl
|
|
Packit |
292933 |
table inet firewalld {
|
|
Packit |
292933 |
chain filter_IN_public_allow {
|
|
Packit |
292933 |
tcp dport 22 ct state new,untracked accept
|
|
Packit |
292933 |
ip6 daddr fe80::/64 udp dport 546 ct state new,untracked accept
|
|
Packit |
292933 |
tcp dport 9090 ct state new,untracked accept
|
|
Packit |
292933 |
icmp type echo-request accept
|
|
Packit |
292933 |
icmpv6 type echo-request accept
|
|
Packit |
292933 |
icmpv6 type nd-neighbor-advert accept
|
|
Packit |
292933 |
icmp type timestamp-request accept
|
|
Packit |
292933 |
}
|
|
Packit |
292933 |
}
|
|
Packit |
292933 |
])
|
|
Packit |
292933 |
IPTABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
|
|
Packit |
292933 |
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
Packit |
292933 |
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
Packit |
292933 |
ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0 icmptype 8
|
|
Packit |
292933 |
ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0 icmptype 13
|
|
Packit |
292933 |
])
|
|
Packit |
292933 |
IP6TABLES_LIST_RULES([filter], [IN_public_allow], 0, [dnl
|
|
Packit |
292933 |
ACCEPT tcp ::/0 ::/0 tcp dpt:22 ctstate NEW,UNTRACKED
|
|
Packit |
292933 |
ACCEPT udp ::/0 fe80::/64 udp dpt:546 ctstate NEW,UNTRACKED
|
|
Packit |
292933 |
ACCEPT tcp ::/0 ::/0 tcp dpt:9090 ctstate NEW,UNTRACKED
|
|
Packit |
292933 |
ACCEPT icmpv6 ::/0 ::/0 ipv6-icmptype 128
|
|
Packit |
292933 |
ACCEPT icmpv6 ::/0 ::/0 ipv6-icmptype 136
|
|
Packit |
292933 |
])
|
|
Packit |
292933 |
|
|
Packit |
292933 |
FWD_END_TEST
|