90ccb18762
Change-Id: I804c3fd1e0c9cbeb454677e7951072ad74391fec
342 lines
13 KiB
Plaintext
342 lines
13 KiB
Plaintext
<securityPolicyHierarchy>
|
|
<name>admin-policy-AA</name>
|
|
<description>8 firewall rules - ping, ssh from anywhere are OK</description>
|
|
<securityPolicy>
|
|
<revision>0</revision>
|
|
<name>security-policy-AA</name>
|
|
<description>Security Policy AA</description>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>false</inheritanceAllowed>
|
|
<precedence>5500</precedence>
|
|
<actionsByCategory>
|
|
<category>firewall</category>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>dhcp-in</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>1</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>DHCP-Client</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>UDP</applicationProtocol>
|
|
<value>68</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>DHCP-Server</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>UDP</applicationProtocol>
|
|
<value>67</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>inbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>dhcp-out</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>2</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>DHCP-Client</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>UDP</applicationProtocol>
|
|
<value>68</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>DHCP-Server</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>UDP</applicationProtocol>
|
|
<value>67</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>outbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>ping-in</name>
|
|
<description>Everyone can ping me</description>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>3</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>ICMP Echo</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>ICMP</applicationProtocol>
|
|
<value>echo-request</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>ICMP Redirect</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>ICMP</applicationProtocol>
|
|
<value>redirect</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>ICMP Echo Reply</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>ICMP</applicationProtocol>
|
|
<value>echo-reply</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>inbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>ping-out</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>4</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>ICMP Echo</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>ICMP</applicationProtocol>
|
|
<value>echo-request</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>ICMP Redirect</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>ICMP</applicationProtocol>
|
|
<value>redirect</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>ICMP Echo Reply</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>ICMP</applicationProtocol>
|
|
<value>echo-reply</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>outbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>ssh-in-ok</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>5</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>SSH</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>TCP</applicationProtocol>
|
|
<value>22</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>inbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>ssh-out-ok</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>6</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>SSH</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>TCP</applicationProtocol>
|
|
<value>22</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>outbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>HTTP-ok</name>
|
|
<description>All can http(s) me</description>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>7</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>HTTP</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>TCP</applicationProtocol>
|
|
<value>80</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>HTTPS</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>TCP</applicationProtocol>
|
|
<value>443</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>inbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>sorry-nothing-allowed</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>8</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>reject</action>
|
|
<direction>inbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
</actionsByCategory>
|
|
<statusesByCategory>
|
|
<category>firewall</category>
|
|
<status>in_sync</status>
|
|
</statusesByCategory>
|
|
</securityPolicy>
|
|
</securityPolicyHierarchy>
|