<!-- Firewall configuration information -->
<ConfigRoot>

  <!-- Known and blessed servives -->

  <service id='0000'>
    <id>sshServer</id>
    <rule>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>22</port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0001'>
    <id>sshClient</id>
    <rule>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>22</port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0002'>
    <id>ftpServer</id>
    <rule>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>21</port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0003'>
    <id>ftpClient</id>
    <rule>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>21</port>
      <flags>-m conntrack --ctstate NEW,RELATED</flags>
    </rule>
  </service>

  <service id='0004'>
    <id>nfsClient</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>111</port>
    </rule>    
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>2049</port>
    </rule>    
    <rule id='0002'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>
        <begin>0</begin>
        <end>65535</end>
      </port>
    </rule>    
    <rule id='0003'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>111</port>
    </rule>    
    <rule id='0004'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>2049</port>
    </rule>
    <rule id='0005'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>0</begin>
        <end>65535</end>
      </port>
    </rule>    
  </service>

  <service id='0005'>
    <id>smbClient</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>137</begin>
        <end>139</end>
      </port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>445</port>
    </rule>
  </service>

  <service id='0006'>
    <id>snmpd</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>161</port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>162</port>
    </rule>
  </service>

  <service id='0007'>
    <id>vncServer</id>
    <rule>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <!-- Allow VNC sessions 0-64 -->
        <begin>5900</begin>
        <end>5964</end>
      </port>
    </rule>
  </service>    

  <service id='0008'>
    <id>nisClient</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>111</port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>111</port>
    </rule>
    <rule id='0002'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>
        <begin>0</begin>
        <end>65535</end>
      </port>
    </rule>
    <rule id='0003'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>0</begin>
        <end>65535</end>
      </port>
    </rule>
  </service>    

  <service id='0009'>
    <id>ntpClient</id>
    <rule>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>123</port>
    </rule>
  </service>    

  <service id='0010'>
    <id>telnetClient</id>
    <rule>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>23</port>
    </rule>
  </service>    

  <service id='0011'>
    <id>LicenseClient</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>27000</port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>27010</port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <!-- First-party optional services -->

  <service id='0012'>
    <id>CIMHttpServer</id>
    <rule>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>5988</port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0013'>
    <id>CIMHttpsServer</id>
    <rule>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>5989</port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0014'>
    <id>CIMSLP</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>427</port>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <port type='src'>427</port>
    </rule>
    <rule id='0002'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>427</port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0003'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='src'>427</port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0015'>
    <id>swISCSIClient</id>
    <rule>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>3260</port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0016'>
    <id>vpxHeartbeats</id>
    <rule>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>902</port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <!-- AAM stuff should be added by the vpxa RPM -->
  <service id='0020'>
    <id>AAMClient</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>2050</begin>
        <end>5000</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>
        <begin>2050</begin>
        <end>5000</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0002'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>8042</begin>
        <end>8045</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0003'>
      <direction>outbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>
        <begin>8042</begin>
        <end>8045</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0004'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>2050</begin>
        <end>5000</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0005'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>
        <begin>2050</begin>
        <end>5000</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0006'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>8042</begin>
        <end>8045</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0007'>
      <direction>inbound</direction>
      <protocol>udp</protocol>
      <port type='dst'>
        <begin>8042</begin>
        <end>8045</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <!-- Backup agents -->

  <service id='0021'>
    <id>veritasNetBackup</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>13732</port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0001'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>13783</port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0002'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>13720</port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0003'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>13734</port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0022'>
    <id>veritasBackupExec</id>
    <rule>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>10000</begin>
        <end>10200</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0023'>
    <id>TSM</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>1500</port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>1500</port>
      <flags>-m state --state NEW</flags>
    </rule>
        <rule id='0002'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>1581</begin>
        <end>1583</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0003'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>1581</begin>
        <end>1583</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0024'>
    <id>commvaultStatic</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>8400</begin>
        <end>8403</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>8400</begin>
        <end>8403</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0025'>
    <id>commvaultDynamic</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>8600</begin>
        <end>8619</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>8600</begin>
        <end>8619</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0026'>
    <id>activeDirectorKerberos</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>464</port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>88</port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <service id='0027'>
    <id>kerberos</id>
    <rule id='0000'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>749</port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>88</port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>

  <!-- Needs more help...
  <service id='0026'>
    <id>legatoNetWorker</id>
    <rule>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>XXX</port>
      <flags>-m state \-\-state NEW</flags>
    </rule>
  </service>
  -->


<service id='0028'>
    <id>VmmService</id>
    <rule id='0000'>
      <direction>inbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>1124</begin>
        <end>1126</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
    <rule id='0001'>
      <direction>outbound</direction>
      <protocol>tcp</protocol>
      <port type='dst'>
        <begin>1124</begin>
        <end>1126</end>
      </port>
      <flags>-m state --state NEW</flags>
    </rule>
  </service>
  
</ConfigRoot>                                                                                

