2005-05-16 01:20:30 +02:00
|
|
|
#
|
|
|
|
# Shorewall version 2.4 - Routing Rules
|
|
|
|
#
|
|
|
|
# /etc/shorewall/routes
|
|
|
|
#
|
|
|
|
# Entries in this file cause packets to be routed in non-standard
|
|
|
|
# ways.
|
|
|
|
#
|
|
|
|
# I M P O R T A N T ! ! ! !
|
|
|
|
#
|
|
|
|
# In order to use entries in this file, your kernel and iptables must
|
|
|
|
# have ROUTE target support.
|
|
|
|
#
|
2005-05-16 15:52:30 +02:00
|
|
|
# To omit any column, enter "-" in that column.
|
|
|
|
#
|
2005-05-16 01:20:30 +02:00
|
|
|
# Columns are:
|
|
|
|
#
|
|
|
|
#
|
|
|
|
# SOURCE Source of the packet. May be any of the following:
|
|
|
|
#
|
|
|
|
# - A host or network address
|
|
|
|
# - A network interface name.
|
|
|
|
# - The name of an ipset prefaced with "+"
|
|
|
|
# - $FW (for packets originating on the firewall)
|
|
|
|
# - A MAC address in Shorewall format
|
|
|
|
# - A range of IP addresses (assuming that your
|
|
|
|
# kernel and iptables support range match)
|
|
|
|
# - A network interface name followed by ":"
|
|
|
|
# and an address or address range.
|
|
|
|
#
|
|
|
|
# DEST Destination of the packet. May be any of the
|
|
|
|
# following:
|
|
|
|
#
|
|
|
|
# - A host or network address
|
|
|
|
# - A network interface name (determined from
|
|
|
|
# routing table(s))
|
|
|
|
# - The name of an ipset prefaced with "+"
|
|
|
|
# - A network interface name followed by ":"
|
|
|
|
# and an address or address range.
|
|
|
|
#
|
|
|
|
# PROTO Protocol - Must be "tcp", "udp", "icmp", "ipp2p",
|
|
|
|
# a number, or "all". "ipp2p" requires ipp2p match
|
|
|
|
# support in your kernel and iptables.
|
|
|
|
#
|
|
|
|
# PORT(S) Destination Ports. A comma-separated list of Port
|
|
|
|
# names (from /etc/services), port numbers or port
|
|
|
|
# ranges; if the protocol is "icmp", this column is
|
|
|
|
# interpreted as the destination icmp-type(s).
|
|
|
|
#
|
|
|
|
# If the protocol is ipp2p, this column is interpreted
|
|
|
|
# as an ipp2p option without the leading "--" (example "bit"
|
|
|
|
# for bit-torrent). If no PORT is given, "ipp2p" is
|
|
|
|
# assumed.
|
|
|
|
#
|
|
|
|
# SOURCE PORT(S) (Optional) Source port(s). If omitted,
|
|
|
|
# any source port is acceptable. Specified as a comma-
|
|
|
|
# separated list of port names, port numbers or port
|
|
|
|
# ranges.
|
|
|
|
#
|
2005-05-16 15:52:30 +02:00
|
|
|
# TEST Defines a test on the existing packet or connection mark.
|
|
|
|
# The rule will match only if the test returns true. Tests
|
|
|
|
# have the format [!]<value>[/<mask>][:C]
|
|
|
|
#
|
|
|
|
# Where:
|
|
|
|
#
|
|
|
|
# ! Inverts the test (not equal)
|
|
|
|
# <value> Value of the packet or connection mark.
|
|
|
|
# <mask> A mask to be applied to the mark before
|
|
|
|
# testing
|
|
|
|
# :C Designates a connection mark. If omitted,
|
|
|
|
# the packet mark's value is tested.
|
|
|
|
#
|
2005-05-16 01:20:30 +02:00
|
|
|
# INTERFACE The interface that the packet is to be routed out of.
|
|
|
|
#
|
|
|
|
# GATEWAY The gateway that the packet is to be forewarded through.
|
|
|
|
#
|
|
|
|
# See http://shorewall.net/Shorewall_and_Routing.html for additional information.
|
|
|
|
#######################################################################################
|
2005-05-16 15:52:30 +02:00
|
|
|
#SOURCE DEST PROTO PORT(S) SOURCE TEST INTERFACE GATEWAY
|
|
|
|
# PORT(S)
|
2005-05-16 01:20:30 +02:00
|
|
|
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|