Re: Help with SHOREWALL

From: Bit Twister (BitTwister_at_localhost.localdomain)
Date: 10/12/04

Date: Tue, 12 Oct 2004 15:31:14 GMT

On Tue, 12 Oct 2004 04:48:22 GMT, Jules wrote:
> Wouldn't I have to enable 'norfc1918' on any interfaces? I haven't.

Told you I was guessing, how would I have known. :)

> Besides, wouldn't 10. private networks be common?

True, that was why I suggested 192.168, the ISP could be using 10.
Comcast is using it to chat at my cable modem.

Dang, thought I had seen a flag to set to see shorewall process rules but
cannot find it.

> - remarked out all rules in RULES file
> - put only one entry in the POLICY file - "all all ACCEPT info"

Here are mine without comments
cat policy
fw net ACCEPT
net all DROP info
all all REJECT info

> - remarked out all actions in /usr/share/shorewall/actions.std

Hmmm, as I mis-understand it, you copy those files to /etc/shorwall
and modify them there. the /etc/shorewall files superceed the
/usr/share/shorewall/ files.

cat interfaces
net eth0 detect

cat zones
net Net Internet zone

Relevant Pages

  • Re: Help with SHOREWALL
    ... >>Wouldn't I have to enable 'norfc1918' on any interfaces? ... > Told you I was guessing, ... > cat interfaces ... > net Net Internet zone ...
  • Re: classes and inheritance revisited
    ... Interfaces are just a way to keep multiple inheritance ... I think that both Animal and Cat would be abstract class candidates (did you ... you can have general cats, and still subclass it for HouseCat, which has ...
  • Re: Two PPP connections to the same ISP with same remote gateway
    ... including the two cat /dev/tun commands - then it works for me too. ... And if I don't kill the cat commands, ppp can't use those tun devices because another process has them open. ... It's incredibly frustrating to be limited in this way, given that I'm almost certain that ipfilters source-based routing will get around any routing issues if I could only bring the interfaces up. ...
  • Re: c # interfaces limitations ???
    ... The suggestion is to create a PettableMammal class that is a ... child class of Mammal and implements IPettable, and derive Dog and Cat ... interfaces cause in C# is the pressure to make interfaces ...
  • Re: enumeration order of eth interfaces
    ... > there any way to specify this order myself? ... More detail needed - do all three interfaces use the same driver? ... guessing yes, since otherwise the module mapping suffices to fix the order.) ...