2002-07-05 18:19:19 +02:00
|
|
|
#
|
2003-03-18 02:13:38 +01:00
|
|
|
# Shorewall 1.4 - /etc/shorewall/hosts
|
2002-07-05 18:19:19 +02:00
|
|
|
#
|
2003-03-23 19:50:50 +01:00
|
|
|
# THERE ARE TWO CASES WHERE YOU NEED THIS FILE:
|
|
|
|
#
|
|
|
|
# 1) YOU HAVE MULTIPLE NETWORKS IN THE SAME ZONE CONNECTED TO
|
|
|
|
# A SINGLE INTERFACE AND YOU WANT THE SHOREWALL BOX TO ROUTE
|
|
|
|
# BETWEEN THESE NETWORKS.
|
|
|
|
#
|
|
|
|
# 2) YOU HAVE MORE THAN ONE ZONE CONNECTED THROUGH A SINGLE
|
|
|
|
# INTERFACE.
|
|
|
|
#
|
|
|
|
# IF YOU DON'T HAVE EITHER OF THESE SITUATIONS THEN DON'T TOUCH
|
|
|
|
# THIS FILE.
|
2002-07-05 18:19:19 +02:00
|
|
|
#
|
|
|
|
# This file is used to define zones in terms of subnets and/or
|
|
|
|
# individual IP addresses. Most simple setups don't need to
|
|
|
|
# (should not) place anything in this file.
|
|
|
|
#
|
|
|
|
# ZONE - The name of a zone defined in /etc/shorewall/zones
|
|
|
|
#
|
|
|
|
# HOST(S) - The name of an interface followed by a colon (":") and
|
|
|
|
# either:
|
|
|
|
#
|
|
|
|
# a) The IP address of a host
|
|
|
|
# b) A subnetwork in the form
|
|
|
|
# <subnet-address>/<mask width>
|
2003-03-18 02:13:38 +01:00
|
|
|
#
|
2002-07-05 18:19:19 +02:00
|
|
|
# The interface must be defined in the
|
|
|
|
# /etc/shorewall/interfaces file.
|
|
|
|
#
|
|
|
|
# Examples:
|
|
|
|
#
|
|
|
|
# eth1:192.168.1.3
|
2003-03-18 02:13:38 +01:00
|
|
|
# eth2:192.168.2.0/24
|
2002-07-05 18:19:19 +02:00
|
|
|
#
|
|
|
|
# OPTIONS - A comma-separated list of options. Currently-defined
|
|
|
|
# options are:
|
|
|
|
#
|
2002-11-09 19:24:03 +01:00
|
|
|
# maclist - Connection requests from these hosts
|
|
|
|
# are compared against the contents of
|
|
|
|
# /etc/shorewall/maclist. If this option
|
|
|
|
# is specified, the interface must be
|
|
|
|
# an ethernet NIC and must be up before
|
|
|
|
# Shorewall is started.
|
2002-07-05 18:19:19 +02:00
|
|
|
#
|
|
|
|
#
|
2003-03-18 02:13:38 +01:00
|
|
|
#ZONE HOST(S) OPTIONS
|
2002-07-05 18:19:19 +02:00
|
|
|
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS LINE -- DO NOT REMOVE
|