From e43c2287d4c524731593070ca0bc1de649aaf524 Mon Sep 17 00:00:00 2001 From: teastep Date: Mon, 12 Feb 2007 22:58:15 +0000 Subject: [PATCH] Tweak for Multi-ISP doc git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@5401 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb --- docs/MultiISP.xml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/docs/MultiISP.xml b/docs/MultiISP.xml index bcbc329bf..0c0df7e22 100644 --- a/docs/MultiISP.xml +++ b/docs/MultiISP.xml @@ -654,7 +654,7 @@ Feb 9 17:23:45 gw.ilinx kernel: ll header: 00:a0:24:2a:1f:72:00:13:5f:07:97:05: If you do this, you may wish to add rules to log and drop packets from the Internet that have source addresses in your local networks. For example, if the local LAN in the above diagram is 192.168.1.0/24, then - you would add this rule: + you would add this rule: #ACTION SOURCE DEST DROP:info net:192.168.1.0/24 all @@ -691,7 +691,8 @@ net net DROP following entries are required in /etc/shorewall/masq if you plan to redirect connections from the firewall using entries in - /etc/shorewall/tcrules. + /etc/shorewall/tcrules or if you specify balance on your providers. #INTERFACE SUBNET ADDRESS eth0 130.252.99.27 206.124.146.176