mirror of
https://gitlab.com/shorewall/code.git
synced 2024-12-15 19:01:19 +01:00
Convert shorewall_quickstart_guide.htm to XML
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@896 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
This commit is contained in:
parent
8e6f7002d2
commit
8c9dc2b2f3
@ -1,66 +1,46 @@
|
||||
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
|
||||
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Language" content="en-us">
|
||||
<meta http-equiv="Content-Type"
|
||||
content="text/html; charset=UTF-8">
|
||||
<meta name="GENERATOR" content="Microsoft FrontPage 5.0">
|
||||
<meta name="ProgId" content="FrontPage.Editor.Document">
|
||||
<head>
|
||||
<meta content="en-us" http-equiv="Content-Language" />
|
||||
|
||||
<meta content="text/html; charset=UTF-8" http-equiv="Content-Type" />
|
||||
|
||||
<title>Shorewall Index</title>
|
||||
<base target="main">
|
||||
<meta name="Microsoft Theme" content="none">
|
||||
</head>
|
||||
<body>
|
||||
<table border="0" cellpadding="0" cellspacing="0"
|
||||
style="border-collapse: collapse;" width="100%" id="AutoNumber1"
|
||||
bgcolor="#3366ff" height="90">
|
||||
<tbody>
|
||||
<tr>
|
||||
<td width="100%" bgcolor="#ffffff">
|
||||
<ul>
|
||||
<li> <a href="seattlefirewall_index.htm">Home</a></li>
|
||||
<li> <a href="shorewall_features.htm">Features</a></li>
|
||||
<li><a href="Shorewall_Doesnt.html">What it Cannot Do</a><br>
|
||||
</li>
|
||||
<li> <a href="shorewall_prerequisites.htm">Requirements</a></li>
|
||||
<li> <a href="download.htm">Download</a><br>
|
||||
</li>
|
||||
<li> <a href="Install.htm">Installation/Upgrade/</a><br>
|
||||
<a href="Install.htm">Configuration</a><br>
|
||||
</li>
|
||||
<li> <a href="shorewall_quickstart_guide.htm">QuickStart
|
||||
Guides (HOWTOs)</a><br>
|
||||
</li>
|
||||
|
||||
<base target="main" />
|
||||
</head>
|
||||
|
||||
<body><table bgcolor="#3366ff" border="0" cellpadding="0" cellspacing="0"
|
||||
id="AutoNumber1" style="border-collapse: collapse;" width="100%"><tbody><tr>
|
||||
<td bgcolor="#ffffff" width="100%"> <ul> <li> <a
|
||||
href="seattlefirewall_index.htm">Home</a></li> <li> <a
|
||||
href="shorewall_features.htm">Features</a></li> <li><a
|
||||
href="Shorewall_Doesnt.html">What it Cannot Do</a> </li> <li> <a
|
||||
href="shorewall_prerequisites.htm">Requirements</a></li> <li> <a
|
||||
href="download.htm">Download</a> </li> <li> <a href="Install.htm">Installation/Upgrade/</a>
|
||||
<a href="Install.htm">Configuration</a> </li> <li> <a
|
||||
href="shorewall_quickstart_guide.htm">QuickStart Guides (HOWTOs)</a> </li>
|
||||
<li> <b><a href="shorewall_quickstart_guide.htm#Documentation">Documentation</a></b></li>
|
||||
<li> <a href="FAQ.htm">FAQs</a></li>
|
||||
<li><a href="useful_links.html">Useful Links</a><br>
|
||||
</li>
|
||||
<li> <a href="troubleshoot.htm">Things to try if it doesn't
|
||||
work</a></li>
|
||||
<li> <a href="errata.htm">Errata</a></li>
|
||||
<li> <a href="upgrade_issues.htm">Upgrade Issues</a></li>
|
||||
<li> <a href="support.htm">Getting help or Answers to Questions</a></li>
|
||||
<li><a href="http://lists.shorewall.net">Mailing Lists</a><a
|
||||
href="http://lists.shorewall.net"> </a><br>
|
||||
</li>
|
||||
<li><a href="shorewall_mirrors.htm">Mirrors</a>
|
||||
<ul>
|
||||
</ul>
|
||||
</li>
|
||||
<li> <a href="News.htm">News Archive</a></li>
|
||||
<li> <a href="Shorewall_CVS_Access.html">CVS Repository</a></li>
|
||||
<li> <a href="quotes.htm">Quotes from Users</a></li>
|
||||
<ul>
|
||||
</ul>
|
||||
<li> <a href="shoreline.htm">About the Author</a></li>
|
||||
<li> <a href="seattlefirewall_index.htm#Donations">Donations</a></li>
|
||||
</ul>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
<p><a href="copyright.htm"><font size="2">Copyright</font> © <font
|
||||
size="2">2001-2003 Thomas M. Eastep.</font></a><br>
|
||||
</p>
|
||||
</body>
|
||||
<li> <a href="FAQ.htm">FAQs</a></li> <li><a href="useful_links.html">Useful
|
||||
Links</a> </li> <li> <a href="troubleshoot.htm">Things to try if it
|
||||
doesn't work</a></li> <li> <a href="errata.htm">Errata</a></li>
|
||||
<li> <a href="upgrade_issues.htm">Upgrade Issues</a></li> <li> <a
|
||||
href="support.htm">Getting help or Answers to Questions</a></li> <li><a
|
||||
href="http://lists.shorewall.net">Mailing Lists</a><a
|
||||
href="http://lists.shorewall.net"> </a> </li> <li><a
|
||||
href="shorewall_mirrors.htm">Mirrors</a> </li> <li> <a href="News.htm">News
|
||||
Archive</a></li> <li> <a href="Shorewall_CVS_Access.html">CVS Repository</a></li>
|
||||
<li> <a href="quotes.htm">Quotes from Users</a></li> <li> <a
|
||||
href="shoreline.htm">About the Author</a></li> <li> <a
|
||||
href="seattlefirewall_index.htm#Donations">Donations</a></li> </ul> </td>
|
||||
</tr></tbody></table>
|
||||
<p>
|
||||
<a href="http://validator.w3.org/check/referer"><img
|
||||
src="http://www.w3.org/Icons/valid-xhtml10"
|
||||
alt="Valid XHTML 1.0!" height="31" width="88" /></a>
|
||||
</p>
|
||||
<p><a href="copyright.htm"><font size="2">Copyright ©
|
||||
2001-2003 Thomas M. Eastep.</font> </a> </p></body>
|
||||
</html>
|
||||
|
@ -69,7 +69,7 @@ define your own actions for rules in /etc/shorewall/rules (shorewall
|
||||
1.4.9 and later).<br>
|
||||
</li>
|
||||
</ul>
|
||||
<h2>Comments</h2>
|
||||
<h2><a name="Comments"></a>Comments</h2>
|
||||
<p>You may place comments in configuration files by making the first
|
||||
non-whitespace character a pound sign ("#"). You may also place
|
||||
comments at the end of any line, again by delimiting the comment from
|
||||
|
@ -1,283 +0,0 @@
|
||||
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Language" content="en-us">
|
||||
<meta name="GENERATOR" content="Microsoft FrontPage 5.0">
|
||||
<meta name="ProgId" content="FrontPage.Editor.Document">
|
||||
<meta http-equiv="Content-Type"
|
||||
content="text/html; charset=windows-1252">
|
||||
<title>Shorewall QuickStart Guide</title>
|
||||
<meta name="Microsoft Theme" content="none">
|
||||
</head>
|
||||
<body>
|
||||
<h1 style="text-align: center;">Shorewall QuickStart Guides (HOWTOs)<br>
|
||||
</h1>
|
||||
<p align="center">With thanks to Richard who reminded me once again
|
||||
that we must all first walk before we can run.<br>
|
||||
The French Translations of the single-IP guides are courtesy of Patrice
|
||||
Vetsel<br>
|
||||
The French Translation of the Shorewall Setup Guide is courtesy of
|
||||
Fabien Demassieux.<br>
|
||||
</p>
|
||||
<h2>The Guides</h2>
|
||||
<p>These guides provide step-by-step instructions for configuring
|
||||
Shorewall in common firewall setups.</p>
|
||||
<p>If you have a <font color="#ff0000"><big><big><b>single public IP
|
||||
address</b></big></big></font>:</p>
|
||||
<blockquote>
|
||||
<ul>
|
||||
<li><a href="standalone.htm">Standalone</a> Linux System (<a
|
||||
href="standalone_fr.html">Version Française</a>)</li>
|
||||
<li><a href="two-interface.htm">Two-interface</a> Linux System
|
||||
acting as a firewall/router for a small local network (<a
|
||||
href="two-interface_fr.html">Version Française</a>)</li>
|
||||
<li><a href="three-interface.htm">Three-interface</a> Linux System
|
||||
acting as a firewall/router for a small local network and a DMZ. (<a
|
||||
href="three-interface_fr.html">Version Française</a>)</li>
|
||||
</ul>
|
||||
<p>The above guides are designed to get your first firewall up and
|
||||
running quickly in the three most common Shorewall configurations. If
|
||||
you want to learn more about Shorewall than is explained in the above
|
||||
simple guides, the <a href="shorewall_setup_guide.htm">Shorewall
|
||||
Setup
|
||||
Guide</a> (See Index Below) is for you.</p>
|
||||
</blockquote>
|
||||
<p>If you have <font color="#ff0000"><big><big><b>more than one public
|
||||
IP address</b></big></big></font>:<br>
|
||||
</p>
|
||||
<blockquote>The <a href="shorewall_setup_guide.htm">Shorewall Setup
|
||||
Guide</a> (See Index Below) outlines the steps necessary to set up a
|
||||
firewall where there are multiple public IP addresses involved or if
|
||||
you
|
||||
want to learn more about Shorewall than is explained in the
|
||||
single-address guides above (<a href="shorewall_setup_guide_fr.htm">Version
|
||||
Française</a>).</blockquote>
|
||||
<ul>
|
||||
</ul>
|
||||
<h2><b><a name="Documentation"></a></b>Documentation Index</h2>
|
||||
<p>The following documentation covers a variety of topics and <b>supplements
|
||||
the <a href="shorewall_quickstart_guide.htm">QuickStart Guides</a>
|
||||
described above</b>. Please review the appropriate guide before trying
|
||||
to use this documentation directly.</p>
|
||||
<ul>
|
||||
<li><a href="Accounting.html">Accounting</a><br>
|
||||
</li>
|
||||
<li><a href="Shorewall_and_Aliased_Interfaces.html">Aliased (virtual)
|
||||
Interfaces (e.g., eth0:0)</a><br>
|
||||
</li>
|
||||
<li><a href="blacklisting_support.htm">Blacklisting</a>
|
||||
<ul>
|
||||
<li>Static Blacklisting using /etc/shorewall/blacklist</li>
|
||||
<li>Dynamic Blacklisting using /sbin/shorewall</li>
|
||||
</ul>
|
||||
</li>
|
||||
<li><a href="starting_and_stopping_shorewall.htm">Commands</a>
|
||||
(Description of all /sbin/shorewall commands)</li>
|
||||
<li><a href="configuration_file_basics.htm">Common configuration file
|
||||
features</a> </li>
|
||||
<ul>
|
||||
<li><a href="configuration_file_basics.htm#Comments">Comments in
|
||||
configuration files</a></li>
|
||||
<li><a href="configuration_file_basics.htm#Continuation">Line
|
||||
Continuation</a></li>
|
||||
<li><a href="configuration_file_basics.htm#INCLUDE">INCLUDE
|
||||
Directive</a></li>
|
||||
<li><a href="configuration_file_basics.htm#Ports">Port
|
||||
Numbers/Service Names</a></li>
|
||||
<li><a href="configuration_file_basics.htm#Ranges">Port Ranges</a></li>
|
||||
<li><a href="configuration_file_basics.htm#Variables">Using Shell
|
||||
Variables</a></li>
|
||||
<li><a href="configuration_file_basics.htm#dnsnames">Using DNS Names</a></li>
|
||||
<li><a href="configuration_file_basics.htm#Compliment">Complementing
|
||||
an IP address or Subnet</a></li>
|
||||
<li><a href="configuration_file_basics.htm#Configs">Shorewall
|
||||
Configurations (making a test configuration)</a></li>
|
||||
<li><a href="configuration_file_basics.htm#MAC">Using MAC Addresses
|
||||
in Shorewall</a> </li>
|
||||
</ul>
|
||||
<li><a href="Documentation.htm">Configuration File Reference Manual</a>
|
||||
<ul>
|
||||
<li><a href="Documentation.htm#Variables">params</a></li>
|
||||
<li><font color="#000099"><a href="Documentation.htm#Zones">zones</a></font></li>
|
||||
<li><font color="#000099"><a href="Documentation.htm#Interfaces">interfaces</a></font></li>
|
||||
<li><font color="#000099"><a href="Documentation.htm#Hosts">hosts</a></font></li>
|
||||
<li><font color="#000099"><a href="Documentation.htm#Policy">policy</a></font></li>
|
||||
<li><font color="#000099"><a href="Documentation.htm#Rules">rules</a></font></li>
|
||||
<li><a href="Documentation.htm#Common">common</a></li>
|
||||
<li><font color="#000099"><a href="Documentation.htm#Masq">masq</a></font></li>
|
||||
<li><font color="#000099"><a href="Documentation.htm#ProxyArp">proxyarp</a></font></li>
|
||||
<li><font color="#000099"><a href="Documentation.htm#NAT">nat</a></font></li>
|
||||
<li><font color="#000099"><a href="Documentation.htm#Tunnels">tunnels</a></font></li>
|
||||
<li><a href="traffic_shaping.htm#tcrules">tcrules</a></li>
|
||||
<li><font color="#000099"><a href="Documentation.htm#Conf">shorewall.conf</a></font></li>
|
||||
<li><a href="Documentation.htm#modules">modules</a></li>
|
||||
<li><a href="Documentation.htm#TOS">tos</a> </li>
|
||||
<li><a href="Documentation.htm#Blacklist">blacklist</a></li>
|
||||
<li><a href="Documentation.htm#rfc1918">rfc1918</a></li>
|
||||
<li><a href="Documentation.htm#Routestopped">routestopped</a></li>
|
||||
<li><a href="Accounting.html">accounting</a></li>
|
||||
<li><a href="UserSets.html">usersets and users</a></li>
|
||||
<li><a href="MAC_Validation.html">maclist</a></li>
|
||||
<li><a href="User_defined_Actions.html">actions and
|
||||
action.template</a><br>
|
||||
</li>
|
||||
</ul>
|
||||
</li>
|
||||
<li><a href="CorpNetwork.htm">Corporate Network Example</a>
|
||||
(Contributed by a Graeme Boyle)<br>
|
||||
</li>
|
||||
<li><a href="dhcp.htm">DHCP</a></li>
|
||||
<li><a href="ECN.html">ECN Disabling by host or subnet</a></li>
|
||||
<li><a href="errata.htm">Errata</a><br>
|
||||
</li>
|
||||
<li><font color="#000099"><a href="shorewall_extension_scripts.htm">Extension
|
||||
Scripts</a></font> (How to extend Shorewall without modifying Shorewall
|
||||
code through the use of files in /etc/shorewall --
|
||||
/etc/shorewall/start,
|
||||
/etc/shorewall/stopped, etc.)</li>
|
||||
<li><a href="fallback.htm">Fallback/Uninstall</a></li>
|
||||
<li><a href="FAQ.htm">FAQs</a><br>
|
||||
</li>
|
||||
<li><a href="shorewall_features.htm">Features</a><br>
|
||||
</li>
|
||||
<li><a href="Multiple_Zones.html">Forwarding Traffic on the Same
|
||||
Interface</a><br>
|
||||
</li>
|
||||
<li><a href="FTP.html">FTP and Shorewall</a><br>
|
||||
</li>
|
||||
<li><a href="support.htm">Getting help or answers to questions</a></li>
|
||||
<li>Greater Seattle Linux Users Group Presentation</li>
|
||||
<ul>
|
||||
<li><a href="GSLUG.htm">HTML</a></li>
|
||||
<li><a href="GSLUG.ppt">PowerPoint</a></li>
|
||||
</ul>
|
||||
<li><a href="Install.htm">Installation/Upgrade</a></li>
|
||||
<li><a href="IPSEC.htm">IPSEC</a></li>
|
||||
<li><a href="Shorewall_and_Kazaa.html">Kazaa Filtering</a><br>
|
||||
</li>
|
||||
<li><font color="#000099"><a href="kernel.htm">Kernel Configuration</a></font></li>
|
||||
<li><a href="shorewall_logging.html">Logging</a><br>
|
||||
</li>
|
||||
<li><a href="MAC_Validation.html">MAC Verification</a></li>
|
||||
<li><a href="http://lists.shorewall.net">Mailing Lists</a></li>
|
||||
<li><a href="Multiple_Zones.html">Multiple Zones Through One Interface</a><br>
|
||||
</li>
|
||||
<li><a href="NetfilterOverview.html">Netfilter Overview</a><br>
|
||||
</li>
|
||||
<li><a href="myfiles.htm">My Shorewall Configuration (How I
|
||||
personally use Shorewall)</a></li>
|
||||
<li><font color="#000099"><a href="NAT.htm">One-to-one NAT (Formerly
|
||||
referred to as <span style="font-style: italic;">Static NAT</span>)<br>
|
||||
</a></font></li>
|
||||
<li><a href="OPENVPN.html">OpenVPN</a></li>
|
||||
<li><a href="starting_and_stopping_shorewall.htm">Operating Shorewall</a><br>
|
||||
</li>
|
||||
<li><a href="ping.html">'Ping' Management</a><br>
|
||||
</li>
|
||||
<li><a href="ports.htm">Port Information</a>
|
||||
<ul>
|
||||
<li>Which applications use which ports</li>
|
||||
<li>Ports used by Trojans</li>
|
||||
</ul>
|
||||
</li>
|
||||
<li><a href="PPTP.htm">PPTP</a></li>
|
||||
<li><a href="ProxyARP.htm">Proxy ARP</a></li>
|
||||
<li><a href="shorewall_prerequisites.htm">Requirements</a><br>
|
||||
</li>
|
||||
<li><a href="samba.htm">Samba</a></li>
|
||||
<li><a href="shorewall_setup_guide.htm">Shorewall Setup Guide</a><br>
|
||||
</li>
|
||||
<ul>
|
||||
<li><a href="shorewall_setup_guide.htm#Introduction">1.0
|
||||
Introduction</a></li>
|
||||
<li><a href="shorewall_setup_guide.htm#Concepts">2.0 Shorewall
|
||||
Concepts</a></li>
|
||||
<li><a href="shorewall_setup_guide.htm#Interfaces">3.0 Network
|
||||
Interfaces</a></li>
|
||||
<li><a href="shorewall_setup_guide.htm#Addressing">4.0 Addressing,
|
||||
Subnets and Routing</a>
|
||||
<ul>
|
||||
<li><a href="shorewall_setup_guide.htm#Addresses">4.1 IP
|
||||
Addresses</a></li>
|
||||
<li><a href="shorewall_setup_guide.htm#Subnets">4.2 Subnets</a></li>
|
||||
<li><a href="shorewall_setup_guide.htm#Routing">4.3 Routing</a></li>
|
||||
<li><a href="shorewall_setup_guide.htm#ARP">4.4 Address
|
||||
Resolution Protocol (ARP)</a></li>
|
||||
</ul>
|
||||
<ul>
|
||||
<li><a href="shorewall_setup_guide.htm#RFC1918">4.5 RFC 1918</a></li>
|
||||
</ul>
|
||||
</li>
|
||||
<li><a href="shorewall_setup_guide.htm#Options">5.0 Setting up your
|
||||
Network</a>
|
||||
<ul>
|
||||
<li><a href="shorewall_setup_guide.htm#Routed">5.1 Routed</a></li>
|
||||
</ul>
|
||||
<ul>
|
||||
<li><a href="shorewall_setup_guide.htm#NonRouted">5.2 Non-routed</a>
|
||||
<ul>
|
||||
<li><a href="shorewall_setup_guide.htm#SNAT">5.2.1 SNAT</a></li>
|
||||
<li><a href="shorewall_setup_guide.htm#DNAT">5.2.2 DNAT</a></li>
|
||||
<li><a href="shorewall_setup_guide.htm#ProxyARP">5.2.3
|
||||
Proxy ARP</a></li>
|
||||
<li><a href="shorewall_setup_guide.htm#NAT">5.2.4
|
||||
One-to-one NAT</a></li>
|
||||
</ul>
|
||||
</li>
|
||||
<li><a href="shorewall_setup_guide.htm#Rules">5.3 Rules</a></li>
|
||||
<li><a href="shorewall_setup_guide.htm#OddsAndEnds">5.4 Odds
|
||||
and Ends</a></li>
|
||||
</ul>
|
||||
</li>
|
||||
<li><a href="shorewall_setup_guide.htm#DNS">6.0 DNS</a></li>
|
||||
<li><a href="shorewall_setup_guide.htm#StartingAndStopping">7.0
|
||||
Starting and Stopping the Firewall</a></li>
|
||||
</ul>
|
||||
<li><font color="#000099"><a
|
||||
href="starting_and_stopping_shorewall.htm">Starting/stopping the
|
||||
Firewall</a></font></li>
|
||||
<ul>
|
||||
<li>Description of all /sbin/shorewall commands</li>
|
||||
<li>How to safely test a Shorewall configuration change<br>
|
||||
</li>
|
||||
</ul>
|
||||
<li><a href="Shorewall_Squid_Usage.html">Squid with Shorewall</a></li>
|
||||
<li><a href="Accounting.html">Traffic Accounting</a><br>
|
||||
</li>
|
||||
<li><a href="traffic_shaping.htm">Traffic Shaping/QOS</a></li>
|
||||
<li><a href="troubleshoot.htm">Troubleshooting (Things to try if it
|
||||
doesn't work)</a></li>
|
||||
<li><a href="User_defined_Actions.html">User-defined Actions</a><br>
|
||||
</li>
|
||||
<li><a href="UserSets.html">UID/GID Based Rules</a><br>
|
||||
</li>
|
||||
<li><a href="upgrade_issues.htm">Upgrade Issues</a><br>
|
||||
</li>
|
||||
<li>VPN
|
||||
<ul>
|
||||
<li><a href="IPSEC.htm">IPSEC</a></li>
|
||||
<li><a href="IPIP.htm">GRE and IPIP</a></li>
|
||||
<li><a href="OPENVPN.html">OpenVPN</a><br>
|
||||
</li>
|
||||
<li><a href="PPTP.htm">PPTP</a></li>
|
||||
<li><a href="6to4.htm">6t04</a><br>
|
||||
</li>
|
||||
<li><a href="VPN.htm">IPSEC/PPTP</a> passthrough from a system
|
||||
behind your
|
||||
firewall to a remote network.</li>
|
||||
<li><a href="GenericTunnels.html">Other VPN types</a>.<br>
|
||||
</li>
|
||||
</ul>
|
||||
</li>
|
||||
<li><a href="whitelisting_under_shorewall.htm">White List Creation</a></li>
|
||||
</ul>
|
||||
<p>If you use one of these guides and have a suggestion for improvement
|
||||
<a href="mailto:webmaster@shorewall.net">please let me know</a>.</p>
|
||||
<p><font size="2">Last modified 12/08/2003 - <a href="support.htm">Tom
|
||||
Eastep</a></font></p>
|
||||
<p><a href="copyright.htm"><font size="2">Copyright 2002, 2003 Thomas
|
||||
M. Eastep</font></a><br>
|
||||
</p>
|
||||
<br>
|
||||
</body>
|
||||
</html>
|
424
Shorewall-docs/shorewall_quickstart_guide.xml
Executable file
424
Shorewall-docs/shorewall_quickstart_guide.xml
Executable file
@ -0,0 +1,424 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE article PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd">
|
||||
<article id="IPIP">
|
||||
<articleinfo>
|
||||
<title>Shorewall QuickStart Guides (HOWTOs)</title>
|
||||
|
||||
<authorgroup>
|
||||
<author>
|
||||
<firstname>Tom</firstname>
|
||||
|
||||
<surname>Eastep</surname>
|
||||
</author>
|
||||
</authorgroup>
|
||||
|
||||
<pubdate>2003-12-08</pubdate>
|
||||
|
||||
<copyright>
|
||||
<year>2001</year>
|
||||
|
||||
<year>2002</year>
|
||||
|
||||
<year>2003</year>
|
||||
|
||||
<holder>Thomas M. Eastep</holder>
|
||||
</copyright>
|
||||
|
||||
<legalnotice>
|
||||
<para>Permission is granted to copy, distribute and/or modify this
|
||||
document under the terms of the GNU Free Documentation License, Version
|
||||
1.2 or any later version published by the Free Software Foundation; with
|
||||
no Invariant Sections, with no Front-Cover, and with no Back-Cover
|
||||
Texts. A copy of the license is included in the section entitled "<ulink
|
||||
url="GnuCopyright.htm">GNU Free Documentation License</ulink>".</para>
|
||||
</legalnotice>
|
||||
</articleinfo>
|
||||
|
||||
<para>With thanks to Richard who reminded me once again that we must all
|
||||
first walk before we can run.</para>
|
||||
|
||||
<para>The French Translations of the single-IP guides are courtesy of
|
||||
Patrice Vetsel.</para>
|
||||
|
||||
<para>The French Translation of the Shorewall Setup Guide is courtesy of
|
||||
Fabien Demassieux.</para>
|
||||
|
||||
<section id="Guides">
|
||||
<title>The Guides</title>
|
||||
|
||||
<para>These guides provide step-by-step instructions for configuring
|
||||
Shorewall in common firewall setups.</para>
|
||||
|
||||
<section>
|
||||
<title>If you have a <emphasis role="bold">single public IP address</emphasis></title>
|
||||
|
||||
<para>These guides are designed to get your first firewall up and
|
||||
running quickly in the three most common Shorewall configurations. If
|
||||
you want to learn more about Shorewall than is explained in the above
|
||||
simple guides,  the Shorewall Setup Guide (See Index Below) is
|
||||
for you.<itemizedlist><listitem><para><ulink url="standalone.htm">Standalone</ulink>
|
||||
Linux System (<ulink url="standalone_fr.html">Version Française</ulink>)</para></listitem><listitem><para><ulink
|
||||
url="two-interface.htm">Two-interface</ulink> Linux System acting as a
|
||||
firewall/router for a small local network (<ulink
|
||||
url="two-interface_fr.html">Version Française</ulink>)</para></listitem><listitem><para><ulink
|
||||
url="three-interface.htm">Three-interface</ulink> Linux System acting as
|
||||
a firewall/router for a small local network and a DMZ. (<ulink
|
||||
url="three-interface_fr.html">Version Française</ulink>)</para></listitem></itemizedlist></para>
|
||||
</section>
|
||||
|
||||
<section>
|
||||
<title>If you have more than one public IP address</title>
|
||||
|
||||
<para>The <ulink url="shorewall_setup_guide.htm">Shorewall Setup Guide</ulink>
|
||||
(See Index Below) outlines the steps necessary to set up a firewall
|
||||
where there are multiple public IP addresses involved or if you want to
|
||||
learn more about Shorewall than is explained in the single-address
|
||||
guides above (<ulink url="shorewall_setup_guide_fr.htm">Version
|
||||
Française</ulink>).</para>
|
||||
</section>
|
||||
</section>
|
||||
|
||||
<section id="Documentation">
|
||||
<title>Documentation Index</title>
|
||||
|
||||
<para>The following documentation covers a variety of topics and
|
||||
supplements the <ulink url="#Guides">QuickStart Guides</ulink> described
|
||||
above. Please review the appropriate guide before trying to use this
|
||||
documentation directly.</para>
|
||||
|
||||
<para>If you use one of these guides and have a suggestion for improvement
|
||||
<ulink url="mailto:webmaster@shorewall.net">please let me know</ulink>.</para>
|
||||
|
||||
<itemizedlist>
|
||||
<listitem>
|
||||
<para><ulink url="Accounting.html">Accounting</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="Shorewall_and_Aliased_Interfaces.html">Aliased
|
||||
(virtual) Interfaces (e.g., eth0:0)</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="blacklisting_support.htm">Blacklisting</ulink></para>
|
||||
|
||||
<itemizedlist>
|
||||
<listitem>
|
||||
<para>Static Blacklisting using /etc/shorewall/blacklist</para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para>Dynamic Blacklisting using /sbin/shorewall</para>
|
||||
</listitem>
|
||||
</itemizedlist>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="starting_and_stopping_shorewall.htm">Commands</ulink>
|
||||
(Description of all /sbin/shorewall commands)</para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="configuration_file_basics.htm">Common configuration
|
||||
file features </ulink><itemizedlist><listitem><para><ulink
|
||||
url="configuration_file_basics.htm#Comments">Comments in configuration
|
||||
files</ulink></para></listitem><listitem><para><ulink
|
||||
url="configuration_file_basics.htm#Continuation">Line Continuation</ulink></para></listitem><listitem><para><ulink
|
||||
url="configuration_file_basics.htm#INCLUDE">INCLUDE Directive</ulink></para></listitem><listitem><para><ulink
|
||||
url="configuration_file_basics.htm#Ports">Port Numbers/Service Names</ulink>configuration_file_basics.htm#Ports</para></listitem><listitem><para><ulink
|
||||
url="configuration_file_basics.htm#Ranges">Port Ranges</ulink></para></listitem><listitem><para><ulink
|
||||
url="configuration_file_basics.htm#Variables">Using Shell Variables</ulink></para></listitem><listitem><para><ulink
|
||||
url="configuration_file_basics.htm#dnsnames">Using DNS Names</ulink></para></listitem><listitem><para><ulink
|
||||
url="configuration_file_basics.htm#Compliment">Complementing an IP
|
||||
address or Subnet</ulink></para></listitem><listitem><para><ulink
|
||||
url="configuration_file_basics.htm#Levels">Shorewall Configurations
|
||||
(making a test configuration)</ulink></para></listitem><listitem><para><ulink
|
||||
url="configuration_file_basics.htm#MAC">Using MAC Addresses in
|
||||
Shorewall</ulink></para></listitem></itemizedlist></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="Documentation.htm">Configuration File Reference
|
||||
Manual </ulink><itemizedlist><listitem><para><ulink
|
||||
url="Documentation.htm#Variables">params</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#Zones">zones</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#Interfaces">interfaces</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#Hosts">hosts</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#Policy">policy</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#Rules">rules</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#Common">common</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#Masq">masq</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#ProxyArp">proxyarp</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#NAT">nat</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#Tunnels">tunnels</ulink></para></listitem><listitem><para><ulink
|
||||
url="traffic_shaping.htm#tcrules">tcrules</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#Conf">shorewall.conf</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#modules">modules</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#TOS">tos</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#Blacklist">blacklist</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#rfc1918">rfc1918</ulink></para></listitem><listitem><para><ulink
|
||||
url="Documentation.htm#Routestopped">routestopped</ulink></para></listitem><listitem><para><ulink
|
||||
url="Accounting.html">accounting</ulink></para></listitem><listitem><para><ulink
|
||||
url="UserSets.html">usersets and users</ulink></para></listitem><listitem><para><ulink
|
||||
url="MAC_Validation.html">maclist</ulink></para></listitem><listitem><para><ulink
|
||||
url="User_defined_Actions.html">actions and action.template</ulink></para></listitem></itemizedlist></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="CorpNetwork.htm">Corporate Network Example</ulink>
|
||||
(Contributed by a Graeme Boyle)</para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="dhcp.htm">DHCP</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="ECN.html">ECN Disabling by host or subnet</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="errata.htm">Errata</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="shorewall_extension_scripts.htm">Extension Scripts</ulink>
|
||||
(How to extend Shorewall without modifying Shorewall code through the
|
||||
use of files in /etc/shorewall -- /etc/shorewall/start,
|
||||
/etc/shorewall/stopped, etc.)</para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="fallback.htm">Fallback/Uninstall</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="FAQ.htm">FAQs</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="shorewall_features.htm">Features</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="Multiple_Zones.html">Forwarding Traffic on the Same
|
||||
Interface</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="FTP.html">FTP and Shorewall</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="support.htm">Getting help or answers to questions</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para>Greater Seattle Linux Users Group Presentation</para>
|
||||
|
||||
<itemizedlist>
|
||||
<listitem>
|
||||
<para><ulink url="GSLUG.htm">HTML</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="GSLUG.ppt">PowerPoint</ulink></para>
|
||||
</listitem>
|
||||
</itemizedlist>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="Install.htm">Installation/Upgrade</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="IPSEC.htm">IPSEC</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="Shorewall_and_Kazaa.html">Kazaa Filtering</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="kernel.htm">Kernel Configuration</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="shorewall_logging.html">Logging</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="MAC_Validation.html">MAC Verification</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="http://lists.shorewall.net">Mailing Lists</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="Multiple_Zones.html">Multiple Zones Through One
|
||||
Interface</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="myfiles.htm">My Shorewall Configuration</ulink> (How
|
||||
I personally use Shorewall)</para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="NetfilterOverview.html">Netfilter Overview</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="NAT.htm">One-to-one NAT</ulink> (Formerly referred
|
||||
to as Static NAT)</para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="OPENVPN.html">OpenVPN</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="starting_and_stopping_shorewall.htm">Operating
|
||||
Shorewall</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="ping.html">'Ping' Management</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="ports.htm">Port Information</ulink></para>
|
||||
|
||||
<itemizedlist>
|
||||
<listitem>
|
||||
<para>Which applications use which ports</para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para>Ports used by Trojans</para>
|
||||
</listitem>
|
||||
</itemizedlist>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="PPTP.htm">PPTP</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="ProxyARP.htm">Proxy ARP</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="shorewall_prerequisites.htm">Requirements</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="samba.htm">Samba</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="shorewall_setup_guide.htm">Shorewall Setup Guide</ulink><itemizedlist><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#Introduction">Introduction</ulink></para></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#Concepts">Shorewall Concepts</ulink></para></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#Interfaces">Network Interfaces</ulink></para></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#Addressing">Addressing, Subnets and
|
||||
Routing</ulink></para><itemizedlist><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#Addresses">IP Addresses</ulink></para></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#Subnets">Subnets</ulink></para></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#Routing">Routing</ulink></para></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#ARP">Address Resolution Protocol (ARP)</ulink></para></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#RFC1918">RFC 1918</ulink></para></listitem></itemizedlist></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#Options">Setting up your Network</ulink></para><itemizedlist><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#Routed">Routed</ulink></para></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#NonRouted">Non-routed</ulink></para><itemizedlist><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#SNAT">SNAT</ulink></para></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#DNAT">DNAT</ulink></para></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#ProxyARP">Proxy ARP</ulink></para></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#NAT">One-to-one NAT</ulink></para></listitem></itemizedlist></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#Rules">Rules</ulink></para></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#OddsAndEnds">Odds and Ends</ulink></para></listitem></itemizedlist></listitem><listitem><para><ulink
|
||||
url="shorewall_setup_guide.htm#DNS">DNS</ulink></para></listitem><listitem><para><ulink
|
||||
url="starting_and_stopping_shorewall.htm">Starting and Stopping the
|
||||
Firewall</ulink></para></listitem></itemizedlist></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="starting_and_stopping_shorewall.htm">Starting/stopping
|
||||
the Firewall</ulink><itemizedlist><listitem><para>Description of all
|
||||
/sbin/shorewall commands</para></listitem><listitem><para>How to
|
||||
safely test a Shorewall configuration change</para></listitem></itemizedlist></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="Shorewall_Squid_Usage.html">Squid with Shorewall</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="Accounting.html">Traffic Accounting</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="traffic_shaping.htm">Traffic Shaping/QOS</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="troubleshoot.htm">Troubleshooting</ulink> (Things to
|
||||
try if it doesn't work)</para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="User_defined_Actions.html">User-defined Actions</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="UserSets.html">UID/GID Based Rules</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="upgrade_issues.htm">Upgrade Issues</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para>VPN</para>
|
||||
|
||||
<itemizedlist>
|
||||
<listitem>
|
||||
<para><ulink url="IPSEC.htm">IPSEC</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="IPIP.htm">GRE and IPIP</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="OPENVPN.html">OpenVPN</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="PPTP.htm">PPTP</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="6to4.htm">6to4</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="VPN.htm">IPSEC/PPTP passthrough from a system
|
||||
behind your firewall to a remote network</ulink></para>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="GenericTunnels.html">Other VPN types</ulink></para>
|
||||
</listitem>
|
||||
</itemizedlist>
|
||||
</listitem>
|
||||
|
||||
<listitem>
|
||||
<para><ulink url="whitelisting_under_shorewall.htm">White List
|
||||
Creation</ulink></para>
|
||||
</listitem>
|
||||
</itemizedlist>
|
||||
</section>
|
||||
</article>
|
@ -29,6 +29,18 @@
|
||||
Texts. A copy of the license is included in the section entitled "<ulink
|
||||
url="GnuCopyright.htm">GNU Free Documentation License</ulink>".</para>
|
||||
</legalnotice>
|
||||
|
||||
<revhistory>
|
||||
<revision>
|
||||
<revnumber>1.1</revnumber>
|
||||
|
||||
<date>2003-12-19</date>
|
||||
|
||||
<authorinitials>TE</authorinitials>
|
||||
|
||||
<revremark>Corrected URL for Newbies List</revremark>
|
||||
</revision>
|
||||
</revhistory>
|
||||
</articleinfo>
|
||||
|
||||
<graphic fileref="images/obrasinf.gif" format="GIF" valign="middle" />
|
||||
@ -266,7 +278,8 @@
|
||||
|
||||
<para><emphasis role="bold">If you are new to Shorewall and have a
|
||||
question or need help with a problem</emphasis>, please post to the <ulink
|
||||
url="???">Shorewall Newbies mailing list</ulink>.</para>
|
||||
url="mailto:shorewall-newbies@lists.shorewall.net">Shorewall Newbies
|
||||
mailing list</ulink>.</para>
|
||||
|
||||
<para><emphasis role="bold">If you run Shorewall under MandrakeSoft Multi
|
||||
Network Firewall (MNF) and you have not purchased an MNF license from
|
||||
@ -278,7 +291,7 @@
|
||||
url="mailto:shorewall-users@lists.shorewall.net">Shorewall users mailing
|
||||
list</ulink>. <emphasis role="bold">IMPORTANT</emphasis>: If you are not
|
||||
subscribed to the list, please say so -- otherwise, you will not be
|
||||
included in any replies. </para>
|
||||
included in any replies.</para>
|
||||
</section>
|
||||
|
||||
<section>
|
||||
@ -292,8 +305,7 @@
|
||||
<title>Subscribing to the Users Mailing List</title>
|
||||
|
||||
<para>To Subscribe to the mailing list go to <ulink
|
||||
url="https://lists.shorewall.net/mailman/listinfo/shorewall-users">https://lists.shorewall.net/mailman/listinfo/shorewall-users</ulink>.
|
||||
</para>
|
||||
url="https://lists.shorewall.net/mailman/listinfo/shorewall-users">https://lists.shorewall.net/mailman/listinfo/shorewall-users</ulink>.</para>
|
||||
</section>
|
||||
|
||||
<section>
|
||||
|
Loading…
Reference in New Issue
Block a user