mirror of
https://gitlab.com/shorewall/code.git
synced 2024-12-20 05:11:03 +01:00
Merge branch 'master' into 4.5.7
This commit is contained in:
commit
46e57d67d8
@ -70,6 +70,11 @@
|
|||||||
url="manpages/shorewall-blacklist.html">blacklist</ulink> - Static
|
url="manpages/shorewall-blacklist.html">blacklist</ulink> - Static
|
||||||
blacklisting.</member>
|
blacklisting.</member>
|
||||||
|
|
||||||
|
<member><ulink
|
||||||
|
url="manpages/shorewall-conntrack.html">conntrack</ulink> - Specify
|
||||||
|
helpers for connections or exempt certain traffic from netfilter
|
||||||
|
connection tracking.</member>
|
||||||
|
|
||||||
<member><ulink url="manpages/shorewall-ecn.html">ecn</ulink> -
|
<member><ulink url="manpages/shorewall-ecn.html">ecn</ulink> -
|
||||||
Disabling Explicit Congestion Notification</member>
|
Disabling Explicit Congestion Notification</member>
|
||||||
|
|
||||||
@ -108,7 +113,7 @@
|
|||||||
How to map addresses from one net to another.</member>
|
How to map addresses from one net to another.</member>
|
||||||
|
|
||||||
<member><ulink url="manpages/shorewall-notrack.html">notrack</ulink> -
|
<member><ulink url="manpages/shorewall-notrack.html">notrack</ulink> -
|
||||||
Exclude certain traffic from Netfilter connection tracking</member>
|
Exclude certain traffic from Netfilter connection tracking </member>
|
||||||
|
|
||||||
<member><ulink url="manpages/shorewall-params.html">params</ulink> -
|
<member><ulink url="manpages/shorewall-params.html">params</ulink> -
|
||||||
Assign values to shell variables used in other files.</member>
|
Assign values to shell variables used in other files.</member>
|
||||||
@ -123,9 +128,8 @@
|
|||||||
<member><ulink url="manpages/shorewall-proxyarp.html">proxyarp</ulink>
|
<member><ulink url="manpages/shorewall-proxyarp.html">proxyarp</ulink>
|
||||||
- Define Proxy ARP.</member>
|
- Define Proxy ARP.</member>
|
||||||
|
|
||||||
<member><ulink
|
<member><ulink url="manpages/shorewall-rtrules.html">rtrules</ulink> -
|
||||||
url="manpages/shorewall-rtrules.html">rtrules</ulink> - Define
|
Define routing rules.</member>
|
||||||
routing rules.</member>
|
|
||||||
|
|
||||||
<member><ulink url="manpages/shorewall-routes.html">routes</ulink> -
|
<member><ulink url="manpages/shorewall-routes.html">routes</ulink> -
|
||||||
(Added in Shorewall 4.4.15) Add additional routes to provider routing
|
(Added in Shorewall 4.4.15) Add additional routes to provider routing
|
||||||
|
@ -68,7 +68,11 @@
|
|||||||
|
|
||||||
<member><ulink
|
<member><ulink
|
||||||
url="manpages6/shorewall6-blacklist.html">blacklist</ulink> - Static
|
url="manpages6/shorewall6-blacklist.html">blacklist</ulink> - Static
|
||||||
blacklisting.</member>
|
blacklisting (deprecated)</member>
|
||||||
|
|
||||||
|
<member><ulink url="manpages-conntrack.html">conntrack</ulink> -
|
||||||
|
Specify helpers for connections or exempt certain traffic from
|
||||||
|
netfilter connection tracking.</member>
|
||||||
|
|
||||||
<member><ulink
|
<member><ulink
|
||||||
url="manpages6/shorewall6-exclusion.html">exclusion</ulink> -
|
url="manpages6/shorewall6-exclusion.html">exclusion</ulink> -
|
||||||
@ -92,7 +96,8 @@
|
|||||||
- How to define nested zones.</member>
|
- How to define nested zones.</member>
|
||||||
|
|
||||||
<member><ulink url="manpages6/shorewall6-notrack.html">notrack</ulink>
|
<member><ulink url="manpages6/shorewall6-notrack.html">notrack</ulink>
|
||||||
- Exclude certain traffic from Netfilter6 connection tracking</member>
|
- Exclude certain traffic from Netfilter6 connection tracking
|
||||||
|
(deprecated)</member>
|
||||||
|
|
||||||
<member><ulink url="manpages6/shorewall6-params.html">params</ulink> -
|
<member><ulink url="manpages6/shorewall6-params.html">params</ulink> -
|
||||||
Assign values to shell variables used in other files.</member>
|
Assign values to shell variables used in other files.</member>
|
||||||
@ -108,9 +113,8 @@
|
|||||||
url="manpages6/shorewall6-proxyndp.html">proxyndp</ulink> - Defines
|
url="manpages6/shorewall6-proxyndp.html">proxyndp</ulink> - Defines
|
||||||
Proxy NDP</member>
|
Proxy NDP</member>
|
||||||
|
|
||||||
<member><ulink
|
<member><ulink url="manpages6/shorewall6-rtrules.html">rtrules</ulink>
|
||||||
url="manpages6/shorewall6-rtrules.html">rtrules</ulink> -
|
- Define routing rules.</member>
|
||||||
Define routing rules.</member>
|
|
||||||
|
|
||||||
<member><ulink url="manpages6/shorewall6-routes.html">routes</ulink> -
|
<member><ulink url="manpages6/shorewall6-routes.html">routes</ulink> -
|
||||||
(Added in Shorewall 4.4.15) Add additional routes to provider routing
|
(Added in Shorewall 4.4.15) Add additional routes to provider routing
|
||||||
|
@ -122,7 +122,7 @@
|
|||||||
(shorewall-lite, and shorewall6-lite) will create a directory under
|
(shorewall-lite, and shorewall6-lite) will create a directory under
|
||||||
the specified path name to hold state information.</para>
|
the specified path name to hold state information.</para>
|
||||||
|
|
||||||
<para>Example: </para>
|
<para>Example:</para>
|
||||||
|
|
||||||
<blockquote>
|
<blockquote>
|
||||||
<para>VARDIR=/opt/var/</para>
|
<para>VARDIR=/opt/var/</para>
|
||||||
@ -152,18 +152,18 @@
|
|||||||
<para>?ENDIF</para>
|
<para>?ENDIF</para>
|
||||||
</blockquote>
|
</blockquote>
|
||||||
|
|
||||||
<para> If they are to be processed only if TC_ENABLED=Internal, then
|
<para>If they are to be processed only if TC_ENABLED=Internal, then
|
||||||
enclose them in</para>
|
enclose them in</para>
|
||||||
|
|
||||||
<blockquote>
|
<blockquote>
|
||||||
<para>?IF TC_ENABLED eq 'Internal'</para>
|
<para>?IF TC_ENABLED eq 'Internal'</para>
|
||||||
|
|
||||||
<para> ...</para>
|
<para>...</para>
|
||||||
|
|
||||||
<para>?ENDIF.</para>
|
<para>?ENDIF.</para>
|
||||||
</blockquote>
|
</blockquote>
|
||||||
|
|
||||||
<para> </para>
|
<para></para>
|
||||||
</listitem>
|
</listitem>
|
||||||
|
|
||||||
<listitem>
|
<listitem>
|
||||||
@ -172,27 +172,29 @@
|
|||||||
files are still processed by the compiler.</para>
|
files are still processed by the compiler.</para>
|
||||||
|
|
||||||
<para>Note that blacklist files may be converted to equivalent blrules
|
<para>Note that blacklist files may be converted to equivalent blrules
|
||||||
files using <command>shorewall[6] update -b</command>. </para>
|
files using <command>shorewall[6] update -b</command>.</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
|
|
||||||
<listitem>
|
<listitem>
|
||||||
<para> In Shorewall 4.5.7, the
|
<para>In Shorewall 4.5.7, the
|
||||||
<filename>/etc/shorewall[6]/notrack</filename> file was renamed
|
<filename>/etc/shorewall[6]/notrack</filename> file was renamed
|
||||||
<filename>/etc/shorewall[6]/conntrack</filename>. When upgrading to a
|
<filename>/etc/shorewall[6]/conntrack</filename>. When upgrading to a
|
||||||
release >= 4.5.7, the <filename>conntrack</filename> file will be
|
release >= 4.5.7, the <filename>conntrack</filename> file will be
|
||||||
installed along side of an existing <filename>notrack</filename> file.
|
installed along side of an existing <filename>notrack</filename> file.
|
||||||
When both files exist, a compiler warning is generated:</para>
|
</para>
|
||||||
|
|
||||||
|
<para>If the 'notrack' file is non-empty, a warning message is issued
|
||||||
|
during compilation: </para>
|
||||||
|
|
||||||
<blockquote>
|
<blockquote>
|
||||||
<para>WARNING: Both /etc/shorewall/notrack and
|
<para>WARNING: Non-empty notrack file (...); please move its
|
||||||
/etc/shorewall/conntrack exist; /etc/shorewall/conntrack is
|
contents to the conntrack file </para>
|
||||||
ignored</para>
|
|
||||||
</blockquote>
|
</blockquote>
|
||||||
|
|
||||||
<para>This warning may be eliminated by moving any entries in the
|
<para>This warning can be eliminated by removing the notrack file (if
|
||||||
<filename>notrack</filename> file to the
|
it has no entries), or by moving its entries to the conntrack file and
|
||||||
<filename>conntrack</filename> file and removing the
|
removing the notrack file. Note that the conntrack file is always
|
||||||
<filename>notrack</filename> file. </para>
|
populated with rules </para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</orderedlist>
|
</orderedlist>
|
||||||
</section>
|
</section>
|
||||||
|
Loading…
Reference in New Issue
Block a user