Fix IPMI: add vnc port 5900, http(s) ports 80,443

This commit is contained in:
root
2017-03-18 17:33:51 +01:00
parent b54e85241f
commit c1550a6f9e
5 changed files with 39 additions and 14 deletions

View File

@ -2667,14 +2667,18 @@ echononl "\t\tIPMI Tools (e.g. IPMIView) only out"
if $allow_ipmi_request_out && ! $permit_local_net_to_inet ; then
for _dev in ${ext_if_arr[@]} ; do
$ip6t -A OUTPUT -o $_dev -p udp --dport $ipmi_udp_port -m conntrack --ctstate NEW -j ACCEPT
for _port in ${ipmi_udp_port_arr[@]} ; do
$ip6t -A OUTPUT -o $_dev -p udp --dport $_port -m conntrack --ctstate NEW -j ACCEPT
done
for _port in ${ipmi_tcp_port_arr[@]} ; do
$ip6t -A OUTPUT -o $_dev -p tcp --dport $_port -m conntrack --ctstate NEW -j ACCEPT
done
if $kernel_forward_between_interfaces ; then
$ip6t -A FORWARD -o $_dev -p udp --dport $ipmi_udp_port -m conntrack --ctstate NEW -j ACCEPT
for _port in ${ipmi_udp_port_arr[@]} ; do
$ip6t -A FORWARD -o $_dev -p udp --dport $_port -m conntrack --ctstate NEW -j ACCEPT
done
for _port in ${ipmi_tcp_port_arr[@]} ; do
$ip6t -A FORWARD -o $_dev -p tcp --dport $_port -m conntrack --ctstate NEW -j ACCEPT
done
@ -2696,13 +2700,17 @@ echononl "\t\tIPMI Tools (e.g. IPMIView) local Networks"
if [[ ${#ipmi_server_ip_arr[@]} -gt 0 ]]; then
for _ip in ${ipmi_server_ip_arr[@]} ; do
$ip6t -A OUTPUT -p udp -d $_ip --dport $ipmi_udp_port -m conntrack --ctstate NEW -j ACCEPT
for _port in ${ipmi_udp_port_arr[@]} ; do
$ip6t -A OUTPUT -p udp -d $_ip --dport $_port -m conntrack --ctstate NEW -j ACCEPT
done
for _port in ${ipmi_tcp_port_arr[@]} ; do
$ip6t -A OUTPUT -p tcp -d $_ip --dport $_port -m conntrack --ctstate NEW -j ACCEPT
done
if $kernel_forward_between_interfaces && ! $permit_between_local_networks ; then
$ip6t -A FORWARD -p udp -d $_ip --dport $ipmi_udp_port -m conntrack --ctstate NEW -j ACCEPT
for _port in ${ipmi_udp_port_arr[@]} ; do
$ip6t -A FORWARD -p udp -d $_ip --dport $_port -m conntrack --ctstate NEW -j ACCEPT
done
for _port in ${ipmi_tcp_port_arr[@]} ; do
$ip6t -A FORWARD -p tcp -d $_ip --dport $_port -m conntrack --ctstate NEW -j ACCEPT
done
@ -2710,11 +2718,13 @@ if [[ ${#ipmi_server_ip_arr[@]} -gt 0 ]]; then
# - Rule is needed if (local) interface aliases in use (like eth0:1)
# -
if $local_alias_interfaces ; then
for _port in ${ipmi_udp_port_arr[@]} ; do
$ip6t -A FORWARD -p udp -s $_ip --sport $_port -m conntrack --ctstate NEW -j ACCEPT
done
for _port in ${ipmi_tcp_port_arr[@]} ; do
$ip6t -A FORWARD -p tcp -d $_ip --dport $_port --tcp-flag ACK ACK -j ACCEPT
$ip6t -A FORWARD -p tcp -s $_ip --sport $_port --tcp-flag ACK ACK -j ACCEPT
done
$ip6t -A FORWARD -p udp -s $_ip --sport $ipmi_udp_port -m conntrack --ctstate NEW -j ACCEPT
fi
fi
done