Chris PeBenito b4cd153
attribute netif_type;
Chris PeBenito b4cd153
attribute node_type;
Chris PeBenito b4cd153
attribute port_type;
Chris PeBenito b4cd153
attribute reserved_port_type;
Chris PeBenito b4cd153
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
# tun_tap_device_t is the type of /dev/net/tun/* and /dev/net/tap/*
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
type tun_tap_device_t;
Chris PeBenito b4cd153
devices_make_device_node(tun_tap_device_t)
Chris PeBenito b4cd153
Chris PeBenito b4cd153
########################################
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
# Ports
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
# port_t is the default type of INET port numbers.
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
type port_t, port_type;
Chris PeBenito b4cd153
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
# reserved_port_t is the type of INET port numbers below 1024.
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
type reserved_port_t, port_type, reserved_port_type;
Chris PeBenito b4cd153
Chris PeBenito b4cd153
network_port(amanda, udp,10080, tcp,10080, udp,10081, tcp,10081, tcp,10082, tcp,10083)
Chris PeBenito b4cd153
dnl network_port(biff) # no defined portcon in current strict
Chris PeBenito b4cd153
network_port(dbskkd, tcp,1178)
Chris PeBenito b4cd153
network_port(dhcpc, udp,68)
Chris PeBenito b4cd153
network_port(dhcpd, udp,67)
Chris PeBenito b4cd153
network_port(dict, tcp,2628)
Chris PeBenito b4cd153
network_port(dns, udp,53, tcp,53)
Chris PeBenito b4cd153
network_port(fingerd, tcp,79)
Chris PeBenito b4cd153
network_port(ftp_data, tcp,20)
Chris PeBenito b4cd153
network_port(ftp, tcp,21)
Chris PeBenito b4cd153
network_port(http_cache, tcp,3128, udp,3130, tcp,8080)
Chris PeBenito b4cd153
network_port(http, tcp,80, tcp,443)
Chris PeBenito b4cd153
network_port(inetd_child, tcp,7, udp,7, tcp,9, udp,9, tcp,13, udp,13, tcp,19, udp,19, tcp,37, udp,37, tcp,113, tcp,512, tcp,543, tcp,544, tcp,891, udp,891, tcp,892, udp,892, tcp,2105)
Chris PeBenito b4cd153
network_port(innd, tcp,119)
Chris PeBenito b4cd153
network_port(ipp, tcp,631, udp,631)
Chris PeBenito b4cd153
network_port(kerberos_admin, tcp,464, udp,464, tcp,749)
Chris PeBenito b4cd153
network_port(kerberos_master, tcp,4444, udp,4444)
Chris PeBenito b4cd153
network_port(kerberos, tcp,88, udp,88, tcp,750, udp,750)
Chris PeBenito b4cd153
network_port(ldap, tcp,389, udp,389, tcp,636, udp,636)
Chris PeBenito b4cd153
network_port(mail, tcp,2000)
Chris PeBenito b4cd153
network_port(nmbd, udp,137, udp,138, udp,139)
Chris PeBenito b4cd153
network_port(pop, tcp,106, tcp,109, tcp,110)
Chris PeBenito b4cd153
network_port(portmap, udp,111, tcp,111)
Chris PeBenito b4cd153
network_port(printer, tcp,515)
Chris PeBenito b4cd153
network_port(pxe, udp,4011)
Chris PeBenito b4cd153
network_port(radacct, udp,1646, udp,1813)
Chris PeBenito b4cd153
network_port(radius, udp,1645, udp,1812)
Chris PeBenito b4cd153
network_port(rsh, tcp,514)
Chris PeBenito b4cd153
network_port(smbd, tcp,137-139, tcp,445)
Chris PeBenito b4cd153
network_port(smtp, tcp,25, tcp,465, tcp,587)
Chris PeBenito b4cd153
network_port(snmp, udp,161, udp,162, tcp,199)
Chris PeBenito b4cd153
network_port(ssh, tcp,22)
Chris PeBenito b4cd153
dnl network_port(stunnel) # no defined portcon in current strict
Chris PeBenito b4cd153
network_port(swat, tcp,901)
Chris PeBenito b4cd153
network_port(syslogd, udp,514)
Chris PeBenito b4cd153
network_port(telnetd, tcp,23)
Chris PeBenito b4cd153
network_port(tftp, udp,69)
Chris PeBenito b4cd153
network_port(vnc, tcp,5900)
Chris PeBenito b4cd153
network_port(xserver, tcp,6001, tcp,6002, tcp,6003, tcp,6004, tcp,6005, tcp,6006, tcp,6007, tcp,6008, tcp,6009, tcp,6010, tcp,6011, tcp,6012, tcp,6013, tcp,6014, tcp,6015, tcp,6016, tcp,6017, tcp,6018, tcp,6019)
Chris PeBenito b4cd153
network_port(zebra, tcp,2601)
Chris PeBenito b4cd153
Chris PeBenito b4cd153
# Defaults for reserved ports.  Earlier portcon entries take precedence;
Chris PeBenito b4cd153
# these entries just cover any remaining reserved ports not otherwise
Chris PeBenito b4cd153
# declared or omitted due to removal of a domain.
Chris PeBenito b4cd153
portcon tcp 1-1023 system_u:object_r:reserved_port_t
Chris PeBenito b4cd153
portcon udp 1-1023 system_u:object_r:reserved_port_t
Chris PeBenito b4cd153
Chris PeBenito b4cd153
########################################
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
# Network nodes
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
# node_t is the default type of network nodes.
Chris PeBenito b4cd153
# The node_*_t types are used for specific network
Chris PeBenito b4cd153
# nodes in net_contexts or net_contexts.mls.
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
type node_t, node_type;
Chris PeBenito b4cd153
Chris PeBenito b4cd153
network_node(compat_ipv4, ::, ffff:ffff:ffff:ffff:ffff:ffff::)
Chris PeBenito b4cd153
network_node(inaddr_any, 0.0.0.0, 255.255.255.255)
Chris PeBenito b4cd153
dnl network_node(internal, , ) # no nodecon for this in current strict policy
Chris PeBenito b4cd153
network_node(link_local, fe80::, ffff:ffff:ffff:ffff::, )
Chris PeBenito b4cd153
network_node(lo, 127.0.0.1, 255.255.255.255)
Chris PeBenito b4cd153
network_node(mapped_ipv4, ::ffff:0000:0000, ffff:ffff:ffff:ffff:ffff:ffff::)
Chris PeBenito b4cd153
network_node(multicast, ff00::, ff00::)
Chris PeBenito b4cd153
network_node(site_local, fec0::, ffc0::)
Chris PeBenito b4cd153
network_node(unspec, ::, ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff)
Chris PeBenito b4cd153
Chris PeBenito b4cd153
Chris PeBenito b4cd153
########################################
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
# Network Interfaces:
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
# netif_t is the default type of network interfaces.
Chris PeBenito b4cd153
#
Chris PeBenito b4cd153
type netif_t, netif_type;
Chris PeBenito b4cd153
Chris PeBenito b4cd153
network_interface(lo)
Chris PeBenito b4cd153
network_interface(eth0)
Chris PeBenito b4cd153
network_interface(eth1)
Chris PeBenito b4cd153
network_interface(eth2)
Chris PeBenito b4cd153
network_interface(ippp0)
Chris PeBenito b4cd153
network_interface(ipsec0)
Chris PeBenito b4cd153
network_interface(ipsec1)
Chris PeBenito b4cd153
network_interface(ipsec2)