+my $pve_std_chains = {
+ 'PVEFW-SET-ACCEPT-MARK' => [
+ "-j MARK --set-mark 1",
+ ],
+ 'PVEFW-DropBroadcast' => [
+ # same as shorewall 'Broadcast'
+ # simply DROP BROADCAST/MULTICAST/ANYCAST
+ # we can use this to reduce logging
+ { action => 'DROP', dsttype => 'BROADCAST' },
+ { action => 'DROP', dsttype => 'MULTICAST' },
+ { action => 'DROP', dsttype => 'ANYCAST' },
+ { action => 'DROP', dest => '224.0.0.0/4' },
+ ],
+ 'PVEFW-reject' => [
+ # same as shorewall 'reject'
+ { action => 'DROP', dsttype => 'BROADCAST' },
+ { action => 'DROP', source => '224.0.0.0/4' },
+ { action => 'DROP', proto => 'icmp' },
+ "-p tcp -j REJECT --reject-with tcp-reset",
+ "-p udp -j REJECT --reject-with icmp-port-unreachable",
+ "-p icmp -j REJECT --reject-with icmp-host-unreachable",
+ "-j REJECT --reject-with icmp-host-prohibited",
+ ],
+ 'PVEFW-Drop' => [
+ # same as shorewall 'Drop', which is equal to DROP,
+ # but REJECT/DROP some packages to reduce logging,
+ # and ACCEPT critical ICMP types
+ { action => 'PVEFW-reject', proto => 'tcp', dport => '43' }, # REJECT 'auth'
+ # we are not interested in BROADCAST/MULTICAST/ANYCAST
+ { action => 'PVEFW-DropBroadcast' },
+ # ACCEPT critical ICMP types
+ { action => 'ACCEPT', proto => 'icmp', dport => 'fragmentation-needed' },
+ { action => 'ACCEPT', proto => 'icmp', dport => 'time-exceeded' },
+ # Drop packets with INVALID state
+ "-m conntrack --ctstate INVALID -j DROP",
+ # Drop Microsoft SMB noise
+ { action => 'DROP', proto => 'udp', dport => '135,445', nbdport => 2 },
+ { action => 'DROP', proto => 'udp', dport => '137:139'},
+ { action => 'DROP', proto => 'udp', dport => '1024:65535', sport => 137 },
+ { action => 'DROP', proto => 'tcp', dport => '135,139,445', nbdport => 3 },
+ { action => 'DROP', proto => 'udp', dport => 1900 }, # UPnP
+ # Drop new/NotSyn traffic so that it doesn't get logged
+ "-p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j DROP",
+ # Drop DNS replies
+ { action => 'DROP', proto => 'udp', sport => 53 },
+ ],
+ 'PVEFW-Reject' => [
+ # same as shorewall 'Reject', which is equal to Reject,
+ # but REJECT/DROP some packages to reduce logging,
+ # and ACCEPT critical ICMP types
+ { action => 'PVEFW-reject', proto => 'tcp', dport => '43' }, # REJECT 'auth'
+ # we are not interested in BROADCAST/MULTICAST/ANYCAST
+ { action => 'PVEFW-DropBroadcast' },
+ # ACCEPT critical ICMP types
+ { action => 'ACCEPT', proto => 'icmp', dport => 'fragmentation-needed' },
+ { action => 'ACCEPT', proto => 'icmp', dport => 'time-exceeded' },
+ # Drop packets with INVALID state
+ "-m conntrack --ctstate INVALID -j DROP",
+ # Drop Microsoft SMB noise
+ { action => 'PVEFW-reject', proto => 'udp', dport => '135,445', nbdport => 2 },
+ { action => 'PVEFW-reject', proto => 'udp', dport => '137:139'},
+ { action => 'PVEFW-reject', proto => 'udp', dport => '1024:65535', sport => 137 },
+ { action => 'PVEFW-reject', proto => 'tcp', dport => '135,139,445', nbdport => 3 },
+ { action => 'DROP', proto => 'udp', dport => 1900 }, # UPnP
+ # Drop new/NotSyn traffic so that it doesn't get logged
+ "-p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j DROP",
+ # Drop DNS replies
+ { action => 'DROP', proto => 'udp', sport => 53 },
+ ],
+ 'PVEFW-logflags' => [
+ # same as shorewall logflags action. (fixme: enable/disable logging)
+ "-j LOG --log-prefix \"logflags-dropped:\" --log-level 4 --log-ip-options",
+ "-j DROP",
+ ],
+ 'PVEFW-tcpflags' => [
+ # same as shorewall tcpflags action.
+ # Packets arriving on this interface are checked for som illegal combinations of TCP flags
+ "-p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -g PVEFW-logflags",
+ "-p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -g PVEFW-logflags",
+ "-p tcp -m tcp --tcp-flags SYN,RST SYN,RST -g PVEFW-logflags",
+ "-p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -g PVEFW-logflags",
+ "-p tcp -m tcp --sport 0 --tcp-flags FIN,SYN,RST,ACK SYN -g PVEFW-logflags",
+ ],
+ 'PVEFW-smurflog' => [
+ # same as shorewall smurflog. (fixme: enable/disable logging)
+ "-j LOG --log-prefix \"smurfs-dropped\" --log-level 4",
+ "-j DROP",
+ ],
+ 'PVEFW-smurfs' => [
+ # same as shorewall smurfs action
+ # Filter packets for smurfs (packets with a broadcast address as the source).
+ "-s 0.0.0.0/32 -j RETURN",
+ "-m addrtype --src-type BROADCAST -g PVEFW-smurflog",
+ "-s 224.0.0.0/4 -g PVEFW-smurflog",
+ ],
+};
+
+# iptables -p icmp -h
+my $icmp_type_names = {
+ any => 1,
+ 'echo-reply' => 1,
+ 'destination-unreachable' => 1,
+ 'network-unreachable' => 1,
+ 'host-unreachable' => 1,
+ 'protocol-unreachable' => 1,
+ 'port-unreachable' => 1,
+ 'fragmentation-needed' => 1,
+ 'source-route-failed' => 1,
+ 'network-unknown' => 1,
+ 'host-unknown' => 1,
+ 'network-prohibited' => 1,
+ 'host-prohibited' => 1,
+ 'TOS-network-unreachable' => 1,
+ 'TOS-host-unreachable' => 1,
+ 'communication-prohibited' => 1,
+ 'host-precedence-violation' => 1,
+ 'precedence-cutoff' => 1,
+ 'source-quench' => 1,
+ 'redirect' => 1,
+ 'network-redirect' => 1,
+ 'host-redirect' => 1,
+ 'TOS-network-redirect' => 1,
+ 'TOS-host-redirect' => 1,
+ 'echo-request' => 1,
+ 'router-advertisement' => 1,
+ 'router-solicitation' => 1,
+ 'time-exceeded' => 1,
+ 'ttl-zero-during-transit' => 1,
+ 'ttl-zero-during-reassembly' => 1,
+ 'parameter-problem' => 1,
+ 'ip-header-bad' => 1,
+ 'required-option-missing' => 1,
+ 'timestamp-request' => 1,
+ 'timestamp-reply' => 1,
+ 'address-mask-request' => 1,
+ 'address-mask-reply' => 1,
+};
+