#543: /etc/fuss-server/firewall-allowed-wan-services -------------------------+-------------------------------------------------- Reporter: sabine | Owner: cgabriel Type: enhancement | Status: new Priority: normal | Milestone: Component: Fuss 6.0 | Version: Severity: normal | Keywords: wan services -------------------------+-------------------------------------------------- definire come default (templates di fuss-server) il seguente contenuto del file /etc/fuss-server/firewall-allowed-wan-services[[BR]] 123/udp:Network Time Service[[BR]] 123/tcp:Network Time Service[[BR]] 2628/tcp:dict - Dictionary server[[BR]] 2628/udp:dict - Dictionary server[[BR]] 554/tcp:rtsp - Real Time Stream Control Protocol[[BR]] 554/udp:rtsp - Real Time Stream Control Protocol[[BR]] 1755/udp:ms-streaming [[BR]] 1755/tcp:ms-streaming [[BR]] 1935/udp:Real Time Messaging Protocol[[BR]] 1935/tcp: Real Time Messaging Protocol[[BR]] 5222/tcp:xmpp-client - jabber-client[[BR]] 5222/udp:xmpp-client - jabber-client[[BR]] 13400/tcp:octofussd [[BR]] 13400/udp:octofussd [[BR]] 13402/tcp:octonet [[BR]] 13402/udp:octonet
#543: /etc/fuss-server/firewall-allowed-wan-services -----------------------------+---------------------------------------------- Reporter: sabine | Owner: piccardi Type: enhancement | Status: new Priority: normal | Milestone: Component: Fuss Server 6.0 | Version: Severity: normal | Resolution: Keywords: wan services | -----------------------------+---------------------------------------------- Changes (by sabine):
* owner: cgabriel => piccardi * component: Fuss 6.0 => Fuss Server 6.0
#543: /etc/fuss-server/firewall-allowed-wan-services -----------------------------+---------------------------------------------- Reporter: sabine | Owner: piccardi Type: enhancement | Status: new Priority: normal | Milestone: Component: Fuss Server 6.0 | Version: Severity: normal | Resolution: Keywords: wan services | -----------------------------+----------------------------------------------
Comment(by piccardi):
Ci sono alcune cose su cui mi serve un chiarimento.
Anzitutto non credo che NTP vada su TCP, per cui credo che 123/tcp:Network Time Service non serva. Inoltre io ho attualmente la lista:
123/udp:Network Time Service 2628/tcp:Dictionary Service 554/udp:realplayer 1755/udp:win media 443/udp:deutsche welle 1935/udp:flash streaming
che comprende anche il 443/udp che non so se deve essere mantenuto o meno.
Simone
#543: /etc/fuss-server/firewall-allowed-wan-services -----------------------------+---------------------------------------------- Reporter: sabine | Owner: piccardi Type: enhancement | Status: new Priority: normal | Milestone: Component: Fuss Server 6.0 | Version: Severity: normal | Resolution: Keywords: wan services | -----------------------------+----------------------------------------------
Comment(by sabine):
errore mio :-) - sorry[[BR]][[BR]] ecco il contenuto per il file /etc/fuss-server/firewall-allowed-wan- services:[[BR]][[BR]] 123/udp:Network Time Service[[BR]] 443/udp:https [[BR]] 443/tcp:https [[BR]] 554/tcp:rtsp - Real Time Stream Control Protocol[[BR]] 554/udp:rtsp - Real Time Stream Control Protocol[[BR]] 1755/udp:ms-streaming [[BR]] 1755/tcp:ms-streaming [[BR]] 1935/udp:Real Time Messaging Protocol[[BR]] 1935/tcp: Real Time Messaging Protocol[[BR]] 2628/tcp:dict - Dictionary server[[BR]] 2628/udp:dict - Dictionary server[[BR]] 5222/tcp:xmpp-client - jabber-client[[BR]] 5222/udp:xmpp-client - jabber-client[[BR]] 13400/tcp:octofussd [[BR]] 13400/udp:octofussd [[BR]] 13402/tcp:octonet [[BR]] 13402/udp:octonet
#543: /etc/fuss-server/firewall-allowed-wan-services -----------------------------+---------------------------------------------- Reporter: sabine | Owner: piccardi Type: enhancement | Status: closed Priority: normal | Milestone: Component: Fuss Server 6.0 | Version: Severity: normal | Resolution: fixed Keywords: wan services | -----------------------------+---------------------------------------------- Changes (by piccardi):
* status: new => closed * resolution: => fixed
Comment:
Aggiunti a partire dalla versione 6.0-3 del fuss-server, la ottenete dal solito repository provvisorio.
Ma tenete presente che con queste impostazioni tutti questi servizi sono raggiungibili ovunque siano su internet.
Questo significa ad esempio che qualunque sito in https รจ raggiungibile, senza autenticazione e senza passare dal proxy.
Simone