/sbin/iptables -t nat -A POSTROUTING -j REDNAT
iptables_red
-
+
+ # DMZ pinhole chain. setdmzholes setuid prog adds rules here to allow
+ # ORANGE to talk to GREEN / BLUE.
+ /sbin/iptables -N DMZHOLES
+ if [ "$ORANGE_DEV" != "" ]; then
+ /sbin/iptables -A FORWARD -i $ORANGE_DEV -m state --state NEW -j FORWARDFW
+ fi
+
# PORTFWACCESS chain, used for portforwarding
/sbin/iptables -N PORTFWACCESS
/sbin/iptables -A FORWARD -m state --state NEW -j PORTFWACCESS