Re: shorewall & iptables
From: Kevin (nobody_at_tex.kom)
Date: Wed, 18 Jun 2003 17:45:56 GMT
In article <firstname.lastname@example.org>,
Walter Mautner <email@example.com> writes:
> On Tue, 17 Jun 2003 17:26:28 +0000, Kevin wrote:
> > How can I specify an iptables rule like this with shorewall?
> > iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
> You can only specify the overall behavior in
> /etc/shorewall/shorewall.conf, with a "ALLOWRELATED=yes",
> which results in the following rules on top of each chain:
> ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
I've got that in my shorewall.conf. Yes, NFS needs extra ports
opened up even though I've got portmap and nfs services open.
Earlier someone suggested the above iptables (not shorewall) rule
to let NFS communicate fine on the 37XXX ports that it needs.
-- Unless otherwise noted, the statements herein reflect my personal opinions and not those of any organization with which I may be affiliated.