Subversion Repositories ALCASAR

Compare Revisions

No changes between revisions

Ignore whitespace Rev 2221 → Rev 2223

/scripts/alcasar-bl.sh
1,4 → 1,4
#/bin/bash
#!/bin/bash
 
# $Id$
 
/scripts/alcasar-conf.sh
1,4 → 1,4
#/bin/bash
#!/bin/bash
# $Id$
 
# alcasar-conf.sh
/scripts/alcasar-dhcp.sh
1,4 → 1,4
#/bin/bash
#!/bin/bash
# $Id$
 
# alcasar-dhcp.sh
/scripts/alcasar-dns-local.sh
1,5 → 1,5
#/bin/bash
# $Id: alcasar-dhcp.sh 1484 2014-11-11 23:14:36Z richard $
#!/bin/bash
# $Id$
 
# alcasar-dns-interne.sh
# by Rexy - 3abtux
60,4 → 60,3
exit 1
;;
esac
 
Property changes:
Added: svn:keywords
+Id
\ No newline at end of property
/scripts/alcasar-https.sh
1,4 → 1,4
#/bin/bash
#!/bin/bash
# $Id$
 
# alcasar-dhcp.sh
/scripts/alcasar-importcert.sh
1,14 → 1,16
#!/bin/sh
 
#
# $Id$
#
# alcasar-importcert.sh
# by Raphaël, Hugo, Clément, Bettyna & rexy
 
#
# This script is distributed under the Gnu General Public License (GPL)
 
#
# Script permettant
# - d'importer des certificats sur Alcasar
# - de revenir au certificat par default
 
#
# This script allows
# - to import a certificate in Alcasar
# - to go back to the default certificate
Property changes:
Added: svn:keywords
+Id
\ No newline at end of property
/scripts/alcasar-iptables.sh
58,8 → 58,6
ipset save havp >> $TMP_users_set_save
ipset save havp_bl >> $TMP_users_set_save
ipset save havp_wl >> $TMP_users_set_save
ipset save not_auth_yet >> $TMP_users_set_save
ipset save users_list >> $TMP_users_set_save
ipset save proto_0 >> $TMP_users_set_save
ipset save proto_1 >> $TMP_users_set_save
ipset save proto_2 >> $TMP_users_set_save
143,15 → 141,6
ipset create havp hash:net hashsize 1024
ipset create havp_bl hash:net hashsize 1024
ipset create havp_wl hash:net hashsize 1024
#utilisé pour l'interception des utilisateurs non authentifiés au réseau
#used for intercepting users not connected to the network
ipset create not_auth_yet hash:net hashsize 1024
ipset create users_list list:set
ipset add users_list havp
ipset add users_list havp_wl
ipset add users_list havp_bl
ipset add users_list not_filtered
ipset add users_list not_auth_yet
#pour les filtrages de protocole par utilisateur
ipset create proto_0 hash:net hashsize 1024
ipset create proto_1 hash:net hashsize 1024
163,11 → 152,6
# PREROUTING #
#############################
 
# Redirection des requetes DNS des utilisateurs non connectés dans le DNS-Blackhole
# Redirect users not connected DNS requests in DNS-Blackhole
$IPTABLES -A PREROUTING -t nat -i $TUNIF -m set ! --match-set users_list src -d $PRIVATE_IP -p tcp --dport domain -j REDIRECT --to-port 56
$IPTABLES -A PREROUTING -t nat -i $TUNIF -m set ! --match-set users_list src -d $PRIVATE_IP -p udp --dport domain -j REDIRECT --to-port 56
 
# Marquage des paquets qui tentent d'accéder directement à un serveur sans authentification en mode proxy pour pouvoir les rejeter en INPUT
# Mark packets that attempt to directly access a server without authentication with proxy client to reject them in INPUT rules
#$IPTABLES -A PREROUTING -t mangle -i $TUNIF -s $PRIVATE_NETWORK_MASK -p tcp -m tcp --dport 80 -m string --string 'GET http' --algo bm --from 50 --to 70 -j MARK --set-mark 10
/scripts/alcasar-logout.sh
1,4 → 1,4
#/bin/bash
#!/bin/bash
# $Id$
 
# alcasar-logout.sh
/scripts/alcasar-profil.sh
1,4 → 1,4
#/bin/bash
#!/bin/bash
# $Id$
 
# alcasar-profil.sh
/scripts/alcasar-uninstall.sh
1,4 → 1,3
 
#!/bin/bash
# $Id$
 
/scripts/alcasar-url_filter_bl.sh
1,5 → 1,7
#/bin/bash
#!/bin/bash
 
# Id: $Id$
 
# alcasar-url_filter.sh
# by REXY
# This script is distributed under the Gnu General Public License (GPL)
/scripts/alcasar-url_filter_wl.sh
1,5 → 1,7
#/bin/bash
#!/bin/bash
 
# Id: $Id$
 
# alcasar-url_filter.sh
# by REXY
# This script is distributed under the Gnu General Public License (GPL)
Property changes:
Added: svn:keywords
+Id
\ No newline at end of property