Update My Network article for 5.0

Signed-off-by: Tom Eastep <teastep@shorewall.net>
This commit is contained in:
Tom Eastep 2016-02-18 15:19:06 -08:00
parent d88a00d0cb
commit 6a8a229342

View File

@ -531,7 +531,7 @@ smc:net ip #10.0.1.0/24
<section id="interfaces"> <section id="interfaces">
<title>/etc/shorewall/interfaces</title> <title>/etc/shorewall/interfaces</title>
<para><programlisting>#ZONE INTERFACE BROADCAST OPTIONS <para><programlisting>#ZONE INTERFACE OPTIONS
loc INT_IF dhcp,physical=$INT_IF,ignore=1,wait=5,routefilter,nets=172.20.1.0/24,routeback,tcpflags=0 loc INT_IF dhcp,physical=$INT_IF,ignore=1,wait=5,routefilter,nets=172.20.1.0/24,routeback,tcpflags=0
net COMB_IF optional,sourceroute=0,routefilter=0,arp_ignore=1,proxyarp=0,physical=$COMB_IF,upnp,nosmurfs,tcpflags net COMB_IF optional,sourceroute=0,routefilter=0,arp_ignore=1,proxyarp=0,physical=$COMB_IF,upnp,nosmurfs,tcpflags
net COMC_IF optional,sourceroute=0,routefilter=0,arp_ignore=1,proxyarp=0,physical=$COMC_IF,upnp,nosmurfs,tcpflags,dhcp net COMC_IF optional,sourceroute=0,routefilter=0,arp_ignore=1,proxyarp=0,physical=$COMC_IF,upnp,nosmurfs,tcpflags,dhcp
@ -577,8 +577,7 @@ all all REJECT:Reject $LOG
<section id="accounting"> <section id="accounting">
<title>/etc/shorewall/accounting</title> <title>/etc/shorewall/accounting</title>
<para><programlisting>#ACTION CHAIN SOURCE DESTINATION PROTO DEST SOURCE USER/ MARK IPSEC <para><programlisting>#ACTION CHAIN SOURCE DESTINATION PROTO DPORT SPORT USER MARK IPSEC
# PORT(S) PORT(S) GROUP
?COMMENT ?COMMENT
?SECTION PREROUTING ?SECTION PREROUTING
?SECTION INPUT ?SECTION INPUT
@ -604,7 +603,8 @@ ACCOUNT(loc-net,$INT_NET) - INT_IF COMB_IF
<section id="blacklist"> <section id="blacklist">
<title>/etc/shorewall/blrules</title> <title>/etc/shorewall/blrules</title>
<para><programlisting>WHITELIST net:70.90.191.126 all <para><programlisting>#ACTION SOURCE DEST PROTO DPORT SPORT ORIGDEST RATE USER MARK CONNLIMIT TIME HEADERS SWITCH
WHITELIST net:70.90.191.126 all
BLACKLIST net:+blacklist all BLACKLIST net:+blacklist all
BLACKLIST net all udp 1023:1033,1434,5948,23773 BLACKLIST net all udp 1023:1033,1434,5948,23773
DROP net all tcp 57,1433,1434,2401,2745,3127,3306,3410,4899,5554,5948,6101,8081,9898,23773 DROP net all tcp 57,1433,1434,2401,2745,3127,3306,3410,4899,5554,5948,6101,8081,9898,23773
@ -714,8 +714,7 @@ br0 70.90.191.120/29 70.90.191.121
<title>/etc/shorewall/conntrack</title> <title>/etc/shorewall/conntrack</title>
<para><programlisting>?FORMAT 2 <para><programlisting>?FORMAT 2
#ACTION SOURCE DESTINATION PROTO DEST SOURCE USER/ #ACTION SOURCE DEST PROTO DPORT SPORT
# PORT(S) PORT(S) GROUP
# #
DROP net - udp 3551 DROP net - udp 3551
NOTRACK net - tcp 23 NOTRACK net - tcp 23
@ -832,9 +831,7 @@ ACCEPT COMC_IF $FW udp 67:68</programlistin
<title>/etc/shorewall/rules</title> <title>/etc/shorewall/rules</title>
<para><programlisting>################################################################################################################################################################################################ <para><programlisting>################################################################################################################################################################################################
#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK CONNLIMIT TIME HEADERS SWITCH #ACTION SOURCE DEST PROTO DPORT SPORT ORIGDEST RATE USER MARK CONNLIMIT TIME HEADERS SWITCH
# PORT(S) PORT(S) DEST LIMIT GROUP
################################################################################################################################################################################################
?if $VERSION &lt; 40500 ?if $VERSION &lt; 40500
?SHELL echo " ERROR: Shorewall version is too low" &gt;&amp;2; exit 1 ?SHELL echo " ERROR: Shorewall version is too low" &gt;&amp;2; exit 1
?endif ?endif