My /etc/shorewall/policy just has the following at the end:
#SOURCE DEST POLICY LOG LEVEL LIMIT:BURST
fw net ACCEPT
net all DROP info
# The FOLLOWING POLICY MUST BE LAST
all all REJECT info
#LAST LINE -- ADD YOUR ENTRIES ABOVE THIS LINE -- DO NOT REMOVE
I don't think I changed anything from the defaults when I installed it. As far as the DROP statements, I added that in and have also removed them - they have no effect when I run the port scans.
This is what I get when I run the NeWT Security Scanner - and basically the same when I run the GFI LanGuard scanner:
smtp (25/tcp)
Port is open
Plugin ID : 11219
ftp (21/tcp)
Port is open
Plugin ID : 11219
pop3 (110/tcp)
Port is open
Plugin ID : 11219
http (80/tcp)
Port is open
Plugin ID : 11219
The 80 makes sense, but the others do not.
