Skip to content

fukawi2/checkfw

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

17 Commits
 
 
 
 
 
 
 
 

Repository files navigation

===============================================================================

  DESCRIPTION

A small bash script to check the number of rules in the iptables and/or
ip6tables ruleset. It will first check to see if firewalld is running and
return success if it is. This way the same script can monitor hosts running
firewalld as well as hosts with traditional iptables/ip6tables rulesets.

Useful in conjuction with Nagios and NRPE to ensure firewalls have ruleset
loaded.

Also checks the policy of the INPUT and FORWARD chains to ensure the default
policy is not ACCEPT (default ACCEPT is silly).

===============================================================================

  REQUIREMENTS

Requires support in iptables for the -S flag. This appeared somewhere between
version 1.3.5 and 1.4.7

The Makefile also currently expects to find both 'iptables' and 'ip6tables'
binaries in your PATH, even if you don't intend to use both with this script.
You should either:
  1) Install both iptables and ip6tables
  2) Manually edit the Makefile to remove the one your don't want from the
     DEP_BINS variable around line 5.

===============================================================================

  COPYRIGHT and LICENSE

checkfw is Copyright (C) 2012,2018 Phillip Smith <fukawi2 (at) gmail (dot) com>

See LICENSE file for details.

Releases

No releases published

Packages

No packages published