Ignore:
Timestamp:
May 29, 2015, 1:18:37 AM (9 years ago)
Author:
andersk
Message:
Block outgoing port 25

Exceptions are made for localhost, outgoing.mit.edu, and (temporarily)
the cssa user.

Closes: #403
File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/server/fedora/config/etc/sysconfig/ip6tables

    r2618 r2700  
    55:log-smtp - [0:0]
    66-A log-smtp -o lo -j RETURN
    7 -A OUTPUT -p tcp -m tcp --dport 25 --tcp-flags FIN,SYN,RST,ACK SYN -j log-smtp
     7-A OUTPUT -p tcp -m tcp --dport 25 --syn -j log-smtp
    88-A log-smtp -m owner --uid-owner postfix -j RETURN
    99-A log-smtp -j LOG --log-prefix "SMTP " --log-uid
     10# 536957056=cssa (temporary exception)
     11-A log-smtp -m owner --uid-owner 536957056 -j RETURN
     12-A log-smtp -j REJECT --reject-with icmp6-adm-prohibited
    1013COMMIT
Note: See TracChangeset for help on using the changeset viewer.