mirror of
https://gitlab.com/shorewall/code.git
synced 2025-06-24 03:31:24 +02:00
Update masq manpage to expunge exclusion with an interface name in the SOURCE column.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
This commit is contained in:
parent
0e7a4d56fd
commit
4b6fdf8b72
@ -124,7 +124,7 @@
|
|||||||
<varlistentry>
|
<varlistentry>
|
||||||
<term><emphasis role="bold">SOURCE</emphasis> (Formerly called SUBNET)
|
<term><emphasis role="bold">SOURCE</emphasis> (Formerly called SUBNET)
|
||||||
-
|
-
|
||||||
{<emphasis>interface</emphasis>[:<emphasis>exclusion</emphasis>]|<emphasis>address</emphasis>[<emphasis
|
{<emphasis>interface</emphasis>|<emphasis>address</emphasis>[<emphasis
|
||||||
role="bold">,</emphasis><emphasis>address</emphasis>][<emphasis>exclusion</emphasis>]}</term>
|
role="bold">,</emphasis><emphasis>address</emphasis>][<emphasis>exclusion</emphasis>]}</term>
|
||||||
|
|
||||||
<listitem>
|
<listitem>
|
||||||
@ -137,20 +137,6 @@
|
|||||||
fact. (Shorewall will use your main routing table to determine the
|
fact. (Shorewall will use your main routing table to determine the
|
||||||
appropriate addresses to masquerade).</para>
|
appropriate addresses to masquerade).</para>
|
||||||
|
|
||||||
<para>In order to exclude a address of the specified SOURCE, you may
|
|
||||||
append an <emphasis>exclusion</emphasis> ("!" and a comma-separated
|
|
||||||
list of IP addresses (host or net) that you wish to exclude (see
|
|
||||||
<ulink
|
|
||||||
url="shorewall-exclusion.html">shorewall-exclusion</ulink>(5))).
|
|
||||||
Note that a colon (":") must appear between an
|
|
||||||
<replaceable>interface</replaceable> name and the
|
|
||||||
<replaceable>exclusion</replaceable>;</para>
|
|
||||||
|
|
||||||
<para>Example: eth1:!192.168.1.4,192.168.32.0/27</para>
|
|
||||||
|
|
||||||
<para>In that example traffic from eth1 would be masqueraded unless
|
|
||||||
it came from 192.168.1.4 or 196.168.32.0/27</para>
|
|
||||||
|
|
||||||
<para>The preferred way to specify the SOURCE is to supply one or
|
<para>The preferred way to specify the SOURCE is to supply one or
|
||||||
more host or network addresses separated by comma. You may use ipset
|
more host or network addresses separated by comma. You may use ipset
|
||||||
names preceded by a plus sign (+) to specify a set of hosts.</para>
|
names preceded by a plus sign (+) to specify a set of hosts.</para>
|
||||||
|
Loading…
x
Reference in New Issue
Block a user