mirror of
https://gitlab.com/shorewall/code.git
synced 2024-12-22 06:10:42 +01:00
Reorganize Shorewall Lite docs
This commit is contained in:
parent
37da8b5808
commit
a3d4edfd1f
@ -122,7 +122,7 @@
|
|||||||
<listitem>
|
<listitem>
|
||||||
<para><filename class="directory">configfiles</filename> - A
|
<para><filename class="directory">configfiles</filename> - A
|
||||||
directory containing configuration files to copy to create a <ulink
|
directory containing configuration files to copy to create a <ulink
|
||||||
url="CompiledPrograms.html#Lite">Shorewall-lite export
|
url="Shorewall-Lite.html">Shorewall-lite export
|
||||||
directory.</ulink></para>
|
directory.</ulink></para>
|
||||||
</listitem>
|
</listitem>
|
||||||
|
|
||||||
@ -335,7 +335,7 @@
|
|||||||
<listitem>
|
<listitem>
|
||||||
<para><filename class="directory">configfiles</filename> - A
|
<para><filename class="directory">configfiles</filename> - A
|
||||||
directory containing configuration files to copy to create a <ulink
|
directory containing configuration files to copy to create a <ulink
|
||||||
url="CompiledPrograms.html#Lite">Shorewall6-lite export
|
url="Shorewall-Lite.html">Shorewall6-lite export
|
||||||
directory.</ulink></para>
|
directory.</ulink></para>
|
||||||
</listitem>
|
</listitem>
|
||||||
|
|
||||||
@ -535,7 +535,7 @@
|
|||||||
<listitem>
|
<listitem>
|
||||||
<para><filename>shorecap</filename> - A shell program used for
|
<para><filename>shorecap</filename> - A shell program used for
|
||||||
generating capabilities files. See the <ulink
|
generating capabilities files. See the <ulink
|
||||||
url="CompiledPrograms.html#Lite">Shorewall-lite
|
url="Shorewall-Lite.html">Shorewall-lite
|
||||||
documentation</ulink>.</para>
|
documentation</ulink>.</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
|
|
||||||
@ -725,7 +725,7 @@
|
|||||||
<listitem>
|
<listitem>
|
||||||
<para><filename>shorecap</filename> - A shell program used for
|
<para><filename>shorecap</filename> - A shell program used for
|
||||||
generating capabilities files. See the <ulink
|
generating capabilities files. See the <ulink
|
||||||
url="CompiledPrograms.html#Lite">Shorewall-lite
|
url="Shorewall-Lite.html">Shorewall-lite
|
||||||
documentation</ulink>.</para>
|
documentation</ulink>.</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
|
|
||||||
|
@ -55,7 +55,7 @@
|
|||||||
<tgroup align="left" cols="3">
|
<tgroup align="left" cols="3">
|
||||||
<tbody>
|
<tbody>
|
||||||
<row>
|
<row>
|
||||||
<entry><ulink url="6to4.htm">6to4 and 6in4 Tunnels</ulink></entry>
|
<entry></entry>
|
||||||
|
|
||||||
<entry><ulink url="LXC.html">Linux Containers
|
<entry><ulink url="LXC.html">Linux Containers
|
||||||
(LXC)</ulink></entry>
|
(LXC)</ulink></entry>
|
||||||
@ -65,7 +65,7 @@
|
|||||||
</row>
|
</row>
|
||||||
|
|
||||||
<row>
|
<row>
|
||||||
<entry><ulink url="Accounting.html">Accounting</ulink></entry>
|
<entry><ulink url="6to4.htm">6to4 and 6in4 Tunnels</ulink></entry>
|
||||||
|
|
||||||
<entry><ulink url="Vserver.html">Linux-vserver</ulink></entry>
|
<entry><ulink url="Vserver.html">Linux-vserver</ulink></entry>
|
||||||
|
|
||||||
@ -74,7 +74,7 @@
|
|||||||
</row>
|
</row>
|
||||||
|
|
||||||
<row>
|
<row>
|
||||||
<entry><ulink url="Actions.html">Actions</ulink></entry>
|
<entry><ulink url="Accounting.html">Accounting</ulink></entry>
|
||||||
|
|
||||||
<entry><ulink url="ConnectionRate.html">Limiting Connection
|
<entry><ulink url="ConnectionRate.html">Limiting Connection
|
||||||
Rates</ulink></entry>
|
Rates</ulink></entry>
|
||||||
@ -84,8 +84,7 @@
|
|||||||
</row>
|
</row>
|
||||||
|
|
||||||
<row>
|
<row>
|
||||||
<entry><ulink url="Shorewall_and_Aliased_Interfaces.html">Aliased
|
<entry><ulink url="Actions.html">Actions</ulink></entry>
|
||||||
(virtual) Interfaces (e.g., eth0:0)</ulink></entry>
|
|
||||||
|
|
||||||
<entry><ulink url="shorewall_logging.html">Logging</ulink></entry>
|
<entry><ulink url="shorewall_logging.html">Logging</ulink></entry>
|
||||||
|
|
||||||
@ -93,8 +92,8 @@
|
|||||||
</row>
|
</row>
|
||||||
|
|
||||||
<row>
|
<row>
|
||||||
<entry><ulink url="Anatomy.html">Anatomy of
|
<entry><ulink url="Shorewall_and_Aliased_Interfaces.html">Aliased
|
||||||
Shorewall</ulink></entry>
|
(virtual) Interfaces (e.g., eth0:0)</ulink></entry>
|
||||||
|
|
||||||
<entry><ulink url="Macros.html">Macros</ulink></entry>
|
<entry><ulink url="Macros.html">Macros</ulink></entry>
|
||||||
|
|
||||||
@ -104,8 +103,8 @@
|
|||||||
</row>
|
</row>
|
||||||
|
|
||||||
<row>
|
<row>
|
||||||
<entry><ulink url="Audit.html">AUDIT Target
|
<entry><ulink url="Anatomy.html">Anatomy of
|
||||||
support</ulink></entry>
|
Shorewall</ulink></entry>
|
||||||
|
|
||||||
<entry><ulink url="MAC_Validation.html">MAC
|
<entry><ulink url="MAC_Validation.html">MAC
|
||||||
Verification</ulink></entry>
|
Verification</ulink></entry>
|
||||||
@ -115,8 +114,8 @@
|
|||||||
</row>
|
</row>
|
||||||
|
|
||||||
<row>
|
<row>
|
||||||
<entry><ulink url="traffic_shaping.htm">Bandwidth
|
<entry><ulink url="Audit.html">AUDIT Target
|
||||||
Control</ulink></entry>
|
support</ulink></entry>
|
||||||
|
|
||||||
<entry><ulink url="Manpages.html">Man Pages</ulink></entry>
|
<entry><ulink url="Manpages.html">Man Pages</ulink></entry>
|
||||||
|
|
||||||
@ -125,8 +124,8 @@
|
|||||||
</row>
|
</row>
|
||||||
|
|
||||||
<row>
|
<row>
|
||||||
<entry><ulink
|
<entry><ulink url="traffic_shaping.htm">Bandwidth
|
||||||
url="blacklisting_support.htm">Blacklisting/Whitelisting</ulink></entry>
|
Control</ulink></entry>
|
||||||
|
|
||||||
<entry><ulink url="ManualChains.html">Manual
|
<entry><ulink url="ManualChains.html">Manual
|
||||||
Chains</ulink></entry>
|
Chains</ulink></entry>
|
||||||
@ -137,8 +136,8 @@
|
|||||||
</row>
|
</row>
|
||||||
|
|
||||||
<row>
|
<row>
|
||||||
<entry>Bridge: <ulink
|
<entry><ulink
|
||||||
url="bridge-Shorewall-perl.html">Bridge/Firewall</ulink></entry>
|
url="blacklisting_support.htm">Blacklisting/Whitelisting</ulink></entry>
|
||||||
|
|
||||||
<entry><ulink
|
<entry><ulink
|
||||||
url="two-interface.htm#SNAT">Masquerading</ulink></entry>
|
url="two-interface.htm#SNAT">Masquerading</ulink></entry>
|
||||||
@ -148,8 +147,8 @@
|
|||||||
</row>
|
</row>
|
||||||
|
|
||||||
<row>
|
<row>
|
||||||
<entry>Bridge: <ulink url="SimpleBridge.html">No firewalling of
|
<entry>Bridge: <ulink
|
||||||
traffic between bridge port</ulink></entry>
|
url="bridge-Shorewall-perl.html">Bridge/Firewall</ulink></entry>
|
||||||
|
|
||||||
<entry><ulink url="MultiISP.html">Multiple Internet Connections
|
<entry><ulink url="MultiISP.html">Multiple Internet Connections
|
||||||
from a Single Firewall</ulink></entry>
|
from a Single Firewall</ulink></entry>
|
||||||
@ -158,8 +157,8 @@
|
|||||||
</row>
|
</row>
|
||||||
|
|
||||||
<row>
|
<row>
|
||||||
<entry><ulink url="Build.html">Building Shorewall from
|
<entry>Bridge: <ulink url="SimpleBridge.html">No firewalling of
|
||||||
GIT</ulink></entry>
|
traffic between bridge port</ulink></entry>
|
||||||
|
|
||||||
<entry><ulink url="Multiple_Zones.html">Multiple Zones Through One
|
<entry><ulink url="Multiple_Zones.html">Multiple Zones Through One
|
||||||
Interface</ulink></entry>
|
Interface</ulink></entry>
|
||||||
@ -169,19 +168,18 @@
|
|||||||
</row>
|
</row>
|
||||||
|
|
||||||
<row>
|
<row>
|
||||||
<entry><ulink
|
<entry><ulink url="Build.html">Building Shorewall from
|
||||||
url="starting_and_stopping_shorewall.htm">Commands</ulink></entry>
|
GIT</ulink></entry>
|
||||||
|
|
||||||
<entry><ulink url="MyNetwork.html">My Shorewall
|
<entry><ulink url="MyNetwork.html">My Shorewall
|
||||||
Configuration</ulink></entry>
|
Configuration</ulink></entry>
|
||||||
|
|
||||||
<entry><ulink url="Accounting.html">Traffic
|
<entry></entry>
|
||||||
Accounting</ulink></entry>
|
|
||||||
</row>
|
</row>
|
||||||
|
|
||||||
<row>
|
<row>
|
||||||
<entry><ulink url="CompiledPrograms.html">Compiled Firewall
|
<entry><ulink url="CompiledPrograms.html"><ulink
|
||||||
Programs</ulink></entry>
|
url="starting_and_stopping_shorewall.htm">Commands</ulink></ulink></entry>
|
||||||
|
|
||||||
<entry><ulink url="NetfilterOverview.html">Netfilter
|
<entry><ulink url="NetfilterOverview.html">Netfilter
|
||||||
Overview</ulink></entry>
|
Overview</ulink></entry>
|
||||||
@ -385,7 +383,7 @@
|
|||||||
<entry><ulink url="KVM.html">KVM (Kernel-mode Virtual
|
<entry><ulink url="KVM.html">KVM (Kernel-mode Virtual
|
||||||
Machine)</ulink></entry>
|
Machine)</ulink></entry>
|
||||||
|
|
||||||
<entry><ulink url="CompiledPrograms.html#Lite">Shorewall
|
<entry><ulink url="Shorewall-lite.html">Shorewall
|
||||||
Lite</ulink></entry>
|
Lite</ulink></entry>
|
||||||
|
|
||||||
<entry></entry>
|
<entry></entry>
|
||||||
|
@ -2417,7 +2417,7 @@ etc...</programlisting>
|
|||||||
<para><emphasis role="bold">Answer:</emphasis> Shorewall Lite is a
|
<para><emphasis role="bold">Answer:</emphasis> Shorewall Lite is a
|
||||||
companion product to Shorewall and is designed to allow you to maintain
|
companion product to Shorewall and is designed to allow you to maintain
|
||||||
all Shorewall configuration information on a single system within your
|
all Shorewall configuration information on a single system within your
|
||||||
network. See the <ulink url="CompiledPrograms.html#Lite">Compiled
|
network. See the <ulink url="Shorewall-Lite.html">Compiled
|
||||||
Firewall script documentation</ulink> for details.</para>
|
Firewall script documentation</ulink> for details.</para>
|
||||||
</section>
|
</section>
|
||||||
|
|
||||||
|
@ -646,6 +646,13 @@
|
|||||||
</varlistentry>
|
</varlistentry>
|
||||||
</variablelist>
|
</variablelist>
|
||||||
</blockquote>
|
</blockquote>
|
||||||
|
|
||||||
|
<para>The compile command can be used to stage a new compiled strict that
|
||||||
|
can be activated later using</para>
|
||||||
|
|
||||||
|
<simplelist>
|
||||||
|
<member><command>shorewall restart -f</command></member>
|
||||||
|
</simplelist>
|
||||||
</section>
|
</section>
|
||||||
|
|
||||||
<section id="Shorecap">
|
<section id="Shorecap">
|
||||||
|
@ -968,7 +968,7 @@ DNAT net loc:10.0.0.1 tcp 80 ; mark="88"</
|
|||||||
|
|
||||||
<caution>
|
<caution>
|
||||||
<para>Prior to Shorewall 4.4.17, if you are using <ulink
|
<para>Prior to Shorewall 4.4.17, if you are using <ulink
|
||||||
url="CompiledPrograms.html%23Lite">Shorewall Lite</ulink> , it is not
|
url="Shorewall-Lite.html">Shorewall Lite</ulink> , it is not
|
||||||
advisable to use INCLUDE in the <filename>params</filename> file in an
|
advisable to use INCLUDE in the <filename>params</filename> file in an
|
||||||
export directory if you set EXPORTPARAMS=Yes in <ulink
|
export directory if you set EXPORTPARAMS=Yes in <ulink
|
||||||
url="manpages/shorewall.conf.html">shorewall.conf</ulink> (5). If you do
|
url="manpages/shorewall.conf.html">shorewall.conf</ulink> (5). If you do
|
||||||
@ -1236,7 +1236,7 @@ SHELL cat /etc/shorewall/rules.d/*.rules 2> /dev/null || true</programlisting
|
|||||||
|
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>If you are using <ulink
|
<para>If you are using <ulink
|
||||||
url="CompiledPrograms.html#Lite">Shorewall Lite</ulink> and if the
|
url="Shorewall-Lite.html">Shorewall Lite</ulink> and if the
|
||||||
<filename>params</filename> script needs to set shell variables based
|
<filename>params</filename> script needs to set shell variables based
|
||||||
on the configuration of the firewall system, you can use this
|
on the configuration of the firewall system, you can use this
|
||||||
trick:</para>
|
trick:</para>
|
||||||
@ -1260,7 +1260,7 @@ SHELL cat /etc/shorewall/rules.d/*.rules 2> /dev/null || true</programlisting
|
|||||||
time, there is no way to cause such variables to be expended at run time.
|
time, there is no way to cause such variables to be expended at run time.
|
||||||
Prior to Shorewall 4.4.17, this made it difficult (to impossible) to
|
Prior to Shorewall 4.4.17, this made it difficult (to impossible) to
|
||||||
include dynamic IP addresses in a <ulink
|
include dynamic IP addresses in a <ulink
|
||||||
url="CompiledPrograms.html">Shorewall-lite</ulink> configuration.</para>
|
url="Shorewall-Lite.html">Shorewall-lite</ulink> configuration.</para>
|
||||||
|
|
||||||
<para>Version 4.4.17 implemented <firstterm>Run-time address
|
<para>Version 4.4.17 implemented <firstterm>Run-time address
|
||||||
variables</firstterm>. In configuration files, these variables are
|
variables</firstterm>. In configuration files, these variables are
|
||||||
|
@ -94,7 +94,7 @@
|
|||||||
<listitem>
|
<listitem>
|
||||||
<para>Centrally generated firewall scripts run on the firewalls
|
<para>Centrally generated firewall scripts run on the firewalls
|
||||||
under control of <ulink
|
under control of <ulink
|
||||||
url="CompiledPrograms.html#Lite">Shorewall-lite</ulink>.</para>
|
url="Shorewall-Lite.html">Shorewall-lite</ulink>.</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</itemizedlist>
|
</itemizedlist>
|
||||||
</listitem>
|
</listitem>
|
||||||
|
Loading…
Reference in New Issue
Block a user