2002-08-07 16:28:04 +02:00
|
|
|
#
|
|
|
|
# Shorewall 1.3 - /etc/shorewall/tunnels
|
|
|
|
#
|
|
|
|
# This file defines IPSEC, GRE and IPIP tunnels.
|
|
|
|
#
|
|
|
|
# IPIP and GRE tunnels must be configured on the firewall/gateway itself.
|
|
|
|
# IPSEC endpoints may be defined on the firewall/gateway or on an
|
|
|
|
# internal system.
|
|
|
|
#
|
|
|
|
# The columns are:
|
|
|
|
#
|
2002-11-09 19:10:22 +01:00
|
|
|
# TYPE -- must start in column 1 and be "ipsec", "ipsecnat","ip"
|
|
|
|
# "gre","pptpclient" or "pptpserver"
|
2002-08-07 16:28:04 +02:00
|
|
|
#
|
|
|
|
# ZONE -- The zone of the physical interface through which
|
|
|
|
# tunnel traffic passes. This is normally your internet
|
|
|
|
# zone.
|
|
|
|
#
|
|
|
|
# GATEWAY -- The IP address of the remote tunnel gateway. If the
|
|
|
|
# remote getway has no fixed address (Road Warrior)
|
|
|
|
# then specify the gateway as 0.0.0.0/0.
|
|
|
|
#
|
2002-11-09 19:10:22 +01:00
|
|
|
# GATEWAY ZONES -- Optional. If the gateway system specified in the third
|
2002-08-07 16:28:04 +02:00
|
|
|
# column is a standalone host then this column should
|
2002-11-09 19:10:22 +01:00
|
|
|
# contain a comma-separated list of the names of the zones that
|
|
|
|
# the host might be in. This column only applies to IPSEC tunnels.
|
2002-08-07 16:28:04 +02:00
|
|
|
#
|
|
|
|
# Example 1:
|
|
|
|
#
|
|
|
|
# IPSec tunnel. The remote gateway is 4.33.99.124 and
|
|
|
|
# the remote subnet is 192.168.9.0/24
|
|
|
|
#
|
|
|
|
# ipsec net 4.33.99.124
|
|
|
|
#
|
|
|
|
# Example 2:
|
|
|
|
#
|
|
|
|
# Road Warrior (LapTop that may connect from anywhere)
|
|
|
|
# where the "gw" zone is used to represent the remote
|
|
|
|
# LapTop.
|
|
|
|
#
|
|
|
|
# ipsec net 0.0.0.0/0 gw
|
|
|
|
#
|
|
|
|
# Example 3:
|
|
|
|
#
|
|
|
|
# Host 4.33.99.124 is a standalone system connected
|
|
|
|
# via an ipsec tunnel to the firewall system. The host
|
|
|
|
# is in zone gw.
|
|
|
|
#
|
|
|
|
# ipsec net 4.33.99.124 gw
|
|
|
|
#
|
2002-11-09 19:10:22 +01:00
|
|
|
# Example 4:
|
|
|
|
#
|
|
|
|
# Road Warriors that may belong to zones vpn1, vpn2 or
|
|
|
|
# vpn3. The FreeS/Wan _updown script will add the
|
|
|
|
# host to the appropriate zone using the "shorewall add"
|
|
|
|
# command on connect and will remove the host from the
|
|
|
|
# zone at disconnect time.
|
|
|
|
#
|
|
|
|
# ipsec net 0.0.0.0/0 vpn1,vpn2,vpn3
|
|
|
|
#
|
|
|
|
# Example 5:
|
|
|
|
#
|
|
|
|
# You run the Linux PPTP client on your firewall and
|
|
|
|
# connect to server 192.0.2.221.
|
|
|
|
#
|
|
|
|
# pptpclient net 192.0.2.221
|
|
|
|
#
|
|
|
|
# Example 6:
|
|
|
|
#
|
|
|
|
# You run a PPTP server on your firewall.
|
|
|
|
#
|
|
|
|
# pptpserver net
|
|
|
|
#
|
|
|
|
# TYPE ZONE GATEWAY GATEWAY ZONE
|
2002-08-07 16:28:04 +02:00
|
|
|
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
|