From 36054b77846d7c7f4ce0ebddd7703ed1da46778f Mon Sep 17 00:00:00 2001 From: Tom Eastep Date: Thu, 12 Aug 2010 17:52:22 -0700 Subject: [PATCH] Add additional vserver notes in rules manpages --- manpages/shorewall-rules.xml | 4 +++- manpages6/shorewall6-rules.xml | 9 ++++++++- 2 files changed, 11 insertions(+), 2 deletions(-) diff --git a/manpages/shorewall-rules.xml b/manpages/shorewall-rules.xml index 39f4e0cf0..e08517dcd 100644 --- a/manpages/shorewall-rules.xml +++ b/manpages/shorewall-rules.xml @@ -538,7 +538,9 @@ any is equivalent to all when there are no nested zones. When there are nested zones, any - only refers to top-level zones (those with no parent zones). + only refers to top-level zones (those with no parent zones). Note + that any excludes all vserver + zones, since those zones are nested within the firewall zone. Hosts may also be specified as an IP address range using the syntax diff --git a/manpages6/shorewall6-rules.xml b/manpages6/shorewall6-rules.xml index 42ff2aa36..dbd67643f 100644 --- a/manpages6/shorewall6-rules.xml +++ b/manpages6/shorewall6-rules.xml @@ -359,7 +359,7 @@ SOURCE - {zone|all[{all|any}[+][-]}[:interface][ + any is equivalent to + all when there are no nested zones. + When there are nested zones, any + only refers to top-level zones (those with no parent zones). Note + that any excludes all vserver + zones, since those zones are nested within the firewall zone. + Hosts may also be specified as an IP address range using the syntax lowaddress-highaddress.