Chris PeBenito e181fe
Chris PeBenito 960373
policy_module(corenetwork,1.0)
Chris PeBenito 960373
Chris PeBenito fd89e1
########################################
Chris PeBenito fd89e1
#
Chris PeBenito fd89e1
# Declarations
Chris PeBenito fd89e1
#
Chris PeBenito fd89e1
Chris PeBenito b4cd15
attribute netif_type;
Chris PeBenito b4cd15
attribute node_type;
Chris PeBenito b4cd15
attribute port_type;
Chris PeBenito b4cd15
attribute reserved_port_type;
Chris PeBenito b4cd15
Chris PeBenito 05a5cd
type ppp_device_t;
Chris PeBenito c9428d
dev_node(ppp_device_t)
Chris PeBenito 05a5cd
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
# tun_tap_device_t is the type of /dev/net/tun/* and /dev/net/tap/*
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
type tun_tap_device_t;
Chris PeBenito c9428d
dev_node(tun_tap_device_t)
Chris PeBenito b4cd15
Chris PeBenito b4cd15
########################################
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
# Ports
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
# port_t is the default type of INET port numbers.
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
type port_t, port_type;
Chris PeBenito cabfa5
sid port context_template(system_u:object_r:port_t,s0)
Chris PeBenito b4cd15
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
# reserved_port_t is the type of INET port numbers below 1024.
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
type reserved_port_t, port_type, reserved_port_type;
Chris PeBenito b4cd15
Chris PeBenito 0d0d2b
network_port(amanda, udp,10080,s0, tcp,10080,s0, udp,10081,s0, tcp,10081,s0, tcp,10082,s0, tcp,10083,s0)
Chris PeBenito b4cd15
dnl network_port(biff) # no defined portcon in current strict
Chris PeBenito 0d0d2b
network_port(dbskkd, tcp,1178,s0)
Chris PeBenito 0d0d2b
network_port(dhcpc, udp,68,s0)
Chris PeBenito 0d0d2b
network_port(dhcpd, udp,67,s0)
Chris PeBenito 0d0d2b
network_port(dict, tcp,2628,s0)
Chris PeBenito 0d0d2b
network_port(dns, udp,53,s0, tcp,53,s0)
Chris PeBenito 0d0d2b
network_port(fingerd, tcp,79,s0)
Chris PeBenito 0d0d2b
network_port(ftp_data, tcp,20,s0)
Chris PeBenito 0d0d2b
network_port(ftp, tcp,21,s0)
Chris PeBenito 0d0d2b
network_port(http_cache, tcp,3128,s0, udp,3130,s0, tcp,8080,s0)
Chris PeBenito 0d0d2b
network_port(http, tcp,80,s0, tcp,443,s0)
Chris PeBenito 0d0d2b
network_port(howl, tcp,5335,s0, udp,5353,s0)
Chris PeBenito 05a5cd
dnl network_port(i18n_input) # no defined portcon in current strict
Chris PeBenito 0d0d2b
network_port(inetd_child, tcp,7,s0, udp,7,s0, tcp,9,s0, udp,9,s0, tcp,13,s0, udp,13,s0, tcp,19,s0, udp,19,s0, tcp,37,s0, udp,37,s0, tcp,113,s0, tcp,512,s0, tcp,543,s0, tcp,544,s0, tcp,891,s0, udp,891,s0, tcp,892,s0, udp,892,s0, tcp,2105,s0)
Chris PeBenito 0d0d2b
network_port(innd, tcp,119,s0)
Chris PeBenito 0d0d2b
network_port(ipp, tcp,631,s0, udp,631,s0)
Chris PeBenito 0d0d2b
network_port(kerberos_admin, tcp,464,s0, udp,464,s0, tcp,749,s0)
Chris PeBenito 0d0d2b
network_port(kerberos_master, tcp,4444,s0, udp,4444,s0)
Chris PeBenito 0d0d2b
network_port(kerberos, tcp,88,s0, udp,88,s0, tcp,750,s0, udp,750,s0)
Chris PeBenito 0d0d2b
network_port(ktalkd, udp,517,s0, udp,518,s0)
Chris PeBenito 0d0d2b
network_port(ldap, tcp,389,s0, udp,389,s0, tcp,636,s0, udp,636,s0)
Chris PeBenito 0d0d2b
network_port(mail, tcp,2000,s0)
Chris PeBenito 0d0d2b
network_port(mysqld, tcp,3306,s0)
Chris PeBenito 0d0d2b
network_port(nmbd, udp,137,s0, udp,138,s0, udp,139,s0)
Chris PeBenito 0d0d2b
network_port(pop, tcp,106,s0, tcp,109,s0, tcp,110,s0)
Chris PeBenito 0d0d2b
network_port(portmap, udp,111,s0, tcp,111,s0)
Chris PeBenito 0d0d2b
network_port(postgresql, tcp,5432,s0)
Chris PeBenito 0d0d2b
network_port(printer, tcp,515,s0)
Chris PeBenito 0d0d2b
network_port(pxe, udp,4011,s0)
Chris PeBenito 0d0d2b
network_port(radacct, udp,1646,s0, udp,1813,s0)
Chris PeBenito 0d0d2b
network_port(radius, udp,1645,s0, udp,1812,s0)
Chris PeBenito 0d0d2b
network_port(rsh, tcp,514,s0)
Chris PeBenito 0d0d2b
network_port(rsync, tcp,873,s0, udp,873,s0)
Chris PeBenito 0d0d2b
network_port(smbd, tcp,137-139,s0, tcp,445,s0)
Chris PeBenito 0d0d2b
network_port(smtp, tcp,25,s0, tcp,465,s0, tcp,587,s0)
Chris PeBenito 0d0d2b
network_port(snmp, udp,161,s0, udp,162,s0, tcp,199,s0)
Chris PeBenito 0d0d2b
network_port(ssh, tcp,22,s0)
Chris PeBenito b4cd15
dnl network_port(stunnel) # no defined portcon in current strict
Chris PeBenito 0d0d2b
network_port(swat, tcp,901,s0)
Chris PeBenito 0d0d2b
network_port(syslogd, udp,514,s0)
Chris PeBenito 0d0d2b
network_port(telnetd, tcp,23,s0)
Chris PeBenito 0d0d2b
network_port(tftp, udp,69,s0)
Chris PeBenito 0d0d2b
network_port(vnc, tcp,5900,s0)
Chris PeBenito 0d0d2b
network_port(xserver, tcp,6001,s0, tcp,6002,s0, tcp,6003,s0, tcp,6004,s0, tcp,6005,s0, tcp,6006,s0, tcp,6007,s0, tcp,6008,s0, tcp,6009,s0, tcp,6010,s0, tcp,6011,s0, tcp,6012,s0, tcp,6013,s0, tcp,6014,s0, tcp,6015,s0, tcp,6016,s0, tcp,6017,s0, tcp,6018,s0, tcp,6019,s0)
Chris PeBenito 0d0d2b
network_port(zebra, tcp,2601,s0)
Chris PeBenito b4cd15
Chris PeBenito b4cd15
# Defaults for reserved ports.  Earlier portcon entries take precedence;
Chris PeBenito b4cd15
# these entries just cover any remaining reserved ports not otherwise
Chris PeBenito b4cd15
# declared or omitted due to removal of a domain.
Chris PeBenito 0d0d2b
portcon tcp 1-1023 context_template(system_u:object_r:reserved_port_t, s0)
Chris PeBenito 0d0d2b
portcon udp 1-1023 context_template(system_u:object_r:reserved_port_t, s0)
Chris PeBenito b4cd15
Chris PeBenito b4cd15
########################################
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
# Network nodes
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
# node_t is the default type of network nodes.
Chris PeBenito b4cd15
# The node_*_t types are used for specific network
Chris PeBenito b4cd15
# nodes in net_contexts or net_contexts.mls.
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
type node_t, node_type;
Chris PeBenito cabfa5
sid node context_template(system_u:object_r:node_t,s0)
Chris PeBenito b4cd15
Chris PeBenito 085faa
network_node(compat_ipv4, s0, ::, ffff:ffff:ffff:ffff:ffff:ffff::)
Chris PeBenito 085faa
network_node(inaddr_any, s0, 0.0.0.0, 255.255.255.255)
Chris PeBenito 085faa
dnl network_node(internal, s0, , ) # no nodecon for this in current strict policy
Chris PeBenito 085faa
network_node(link_local, s0, fe80::, ffff:ffff:ffff:ffff::, )
Chris PeBenito 085faa
network_node(lo, s0, 127.0.0.1, 255.255.255.255)
Chris PeBenito 085faa
network_node(mapped_ipv4, s0, ::ffff:0000:0000, ffff:ffff:ffff:ffff:ffff:ffff::)
Chris PeBenito 085faa
network_node(multicast, s0, ff00::, ff00::)
Chris PeBenito 085faa
network_node(site_local, s0, fec0::, ffc0::)
Chris PeBenito 085faa
network_node(unspec, s0, ::, ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff)
Chris PeBenito b4cd15
Chris PeBenito b4cd15
########################################
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
# Network Interfaces:
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
# netif_t is the default type of network interfaces.
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
type netif_t, netif_type;
Chris PeBenito cabfa5
sid netif context_template(system_u:object_r:netif_t,s0)
Chris PeBenito b4cd15
Chris PeBenito 085faa
network_interface(lo, s0)
Chris PeBenito 085faa
network_interface(eth0, s0)
Chris PeBenito 085faa
network_interface(eth1, s0)
Chris PeBenito 085faa
network_interface(eth2, s0)
Chris PeBenito 085faa
network_interface(ippp0, s0)
Chris PeBenito 085faa
network_interface(ipsec0, s0)
Chris PeBenito 085faa
network_interface(ipsec1, s0)
Chris PeBenito 085faa
network_interface(ipsec2, s0)