Changeset 11510 for trunk

Show
Ignore:
Timestamp:
10/16/08 14:47:46 (3 months ago)
Author:
juruen@…
Message:

Add rules to allow DHCP requests from interfaces configured via DHCP

Location:
trunk/client/firewall
Files:
2 modified

Legend:

Unmodified
Added
Removed
  • trunk/client/firewall/ChangeLog

    r11490 r11510  
    110.12.99 
    22        + Add support for reporting  
     3        + Add rules to allow DHCP requests from interfaces configured via DHCP 
    340.12.1 
    45        + Add log decision to firewall rules 
  • trunk/client/firewall/src/EBox/Iptables.pm

    r11412 r11510  
    227227        pf "-A ointernal $new -p udp --dport 53 -d $dns -j ACCEPT"; 
    228228        pf "-A fdns $new -p udp --dport 53 -d $dns -j ACCEPT"; 
     229} 
     230 
     231# Method: setDHCP 
     232# 
     233#       Set output DHCP traffic  
     234# 
     235# Parameters: 
     236# 
     237#       interface -  
     238# 
     239sub setDHCP  
     240{ 
     241        my $self = shift; 
     242        my $interface = shift; 
     243        pf "-A ointernal $new -o $interface -p udp --dport 67 -j ACCEPT"; 
    229244} 
    230245 
     
    400415                $self->nospoof($ifc, $addrs); 
    401416                if ($self->{net}->ifaceMethod($ifc) eq 'dhcp') { 
     417                        $self->setDHCP($ifc); 
    402418                        my $dnsSrvs = $self->{net}->DHCPNameservers($ifc); 
    403419                        foreach my $srv (@{$dnsSrvs}) {