2016-11-05 18:49:43 +03:00
`enable`: `<boolean>` ::
2016-04-01 13:45:24 +03:00
Enable host firewall rules.
2016-11-05 18:49:43 +03:00
`log_level_in`: `<alert | crit | debug | emerg | err | info | nolog | notice | warning>` ::
2016-04-01 13:45:24 +03:00
Log level for incoming traffic.
2016-11-05 18:49:43 +03:00
`log_level_out`: `<alert | crit | debug | emerg | err | info | nolog | notice | warning>` ::
2016-04-01 13:45:24 +03:00
Log level for outgoing traffic.
2019-04-04 18:17:19 +03:00
`log_nf_conntrack`: `<boolean>` ('default =' `0`)::
Enable logging of conntrack information.
2019-11-27 20:46:13 +03:00
`ndp`: `<boolean>` ('default =' `0`)::
2016-04-01 13:45:24 +03:00
2019-11-27 20:46:13 +03:00
Enable NDP (Neighbor Discovery Protocol).
2016-04-01 13:45:24 +03:00
2019-02-01 15:49:11 +03:00
`nf_conntrack_allow_invalid`: `<boolean>` ('default =' `0`)::
Allow invalid packets on connection tracking.
2023-03-20 21:55:17 +03:00
`nf_conntrack_helpers`: `<string>` ('default =' ``)::
Enable conntrack helpers for specific protocols. Supported protocols: amanda, ftp, irc, netbios-ns, pptp, sane, sip, snmp, tftp
2019-11-27 20:46:13 +03:00
`nf_conntrack_max`: `<integer> (32768 - N)` ('default =' `262144`)::
2016-04-01 13:45:24 +03:00
Maximum number of tracked connections.
2019-11-27 20:46:13 +03:00
`nf_conntrack_tcp_timeout_established`: `<integer> (7875 - N)` ('default =' `432000`)::
2016-04-01 13:45:24 +03:00
Conntrack established timeout.
2019-11-27 20:46:13 +03:00
`nf_conntrack_tcp_timeout_syn_recv`: `<integer> (30 - 60)` ('default =' `60`)::
Conntrack syn recv timeout.
2016-11-05 18:49:43 +03:00
`nosmurfs`: `<boolean>` ::
2016-04-01 13:45:24 +03:00
Enable SMURFS filter.
2019-11-27 20:46:13 +03:00
`protection_synflood`: `<boolean>` ('default =' `0`)::
Enable synflood protection
`protection_synflood_burst`: `<integer>` ('default =' `1000`)::
Synflood protection rate burst by ip src.
`protection_synflood_rate`: `<integer>` ('default =' `200`)::
Synflood protection rate syn/sec by ip src.
2016-11-05 18:49:43 +03:00
`smurf_log_level`: `<alert | crit | debug | emerg | err | info | nolog | notice | warning>` ::
2016-04-01 13:45:24 +03:00
Log level for SMURFS filter.
2016-11-05 18:49:43 +03:00
`tcp_flags_log_level`: `<alert | crit | debug | emerg | err | info | nolog | notice | warning>` ::
2016-04-01 13:45:24 +03:00
Log level for illegal tcp flags filter.
2019-11-27 20:46:13 +03:00
`tcpflags`: `<boolean>` ('default =' `0`)::
2016-04-01 13:45:24 +03:00
Filter illegal combinations of TCP flags.