<feed xmlns='http://www.w3.org/2005/Atom'>
<title>fripost-ansible/roles/common/files/etc/network/if-post-down.d/iptables, branch master</title>
<subtitle>Fripost ansible scripts</subtitle>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/'/>
<entry>
<title>Convert firewall to nftables.</title>
<updated>2020-01-23T04:57:01+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2020-01-23T03:29:12+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=7641a5d5d152db349082b1d0ec93a40888b2ef8e'/>
<id>7641a5d5d152db349082b1d0ec93a40888b2ef8e</id>
<content type='text'>
Debian Buster uses the nftables framework by default.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Debian Buster uses the nftables framework by default.
</pre>
</div>
</content>
</entry>
<entry>
<title>Reformulate the headers showing the license.</title>
<updated>2015-06-07T00:50:53+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2013-11-26T03:09:46+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=fd7e94a34b7fa9151d689375d8687d3686786d9b'/>
<id>fd7e94a34b7fa9151d689375d8687d3686786d9b</id>
<content type='text'>
To be clearer, and to follow the recommendation of the FSF, we include
a full header rather than a single sentence.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
To be clearer, and to follow the recommendation of the FSF, we include
a full header rather than a single sentence.
</pre>
</div>
</content>
</entry>
<entry>
<title>Use a dedicated, non-routable, IPv4 for IPSec.</title>
<updated>2015-06-07T00:50:35+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2013-11-03T04:54:11+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=2bcaaf01a5fcc2d2ce618da6af30a43a70d03d80'/>
<id>2bcaaf01a5fcc2d2ce618da6af30a43a70d03d80</id>
<content type='text'>
At the each IPSec end-point the traffic is DNAT'ed to / MASQUERADE'd
from our dedicated IP after ESP decapsulation. Also, some IP tables
ensure that alien (not coming from / going to the tunnel end-point) is
dropped.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
At the each IPSec end-point the traffic is DNAT'ed to / MASQUERADE'd
from our dedicated IP after ESP decapsulation. Also, some IP tables
ensure that alien (not coming from / going to the tunnel end-point) is
dropped.
</pre>
</div>
</content>
</entry>
</feed>
