mirror of
https://gitlab.com/shorewall/code.git
synced 2024-12-24 07:08:53 +01:00
531800538d
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@5134 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
416 lines
13 KiB
XML
416 lines
13 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<!DOCTYPE article PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
|
|
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd">
|
|
<article>
|
|
<!--$Id$-->
|
|
|
|
<articleinfo>
|
|
<title>Shorewall 3.x Documentation</title>
|
|
|
|
<authorgroup>
|
|
<author>
|
|
<firstname>Tom</firstname>
|
|
|
|
<surname>Eastep</surname>
|
|
</author>
|
|
</authorgroup>
|
|
|
|
<pubdate><?dbtimestamp format="Y/m/d"?></pubdate>
|
|
|
|
<copyright>
|
|
<year>2001-2006</year>
|
|
|
|
<holder>Thomas M. Eastep</holder>
|
|
</copyright>
|
|
|
|
<legalnotice>
|
|
<para>Permission is granted to copy, distribute and/or modify this
|
|
document under the terms of the GNU Free Documentation License, Version
|
|
1.2 or any later version published by the Free Software Foundation; with
|
|
no Invariant Sections, with no Front-Cover, and with no Back-Cover
|
|
Texts. A copy of the license is included in the section entitled
|
|
<quote><ulink url="GnuCopyright.htm">GNU Free Documentation
|
|
License</ulink></quote>.</para>
|
|
</legalnotice>
|
|
</articleinfo>
|
|
|
|
<section>
|
|
<title>FAQs</title>
|
|
|
|
<itemizedlist>
|
|
<listitem>
|
|
<para><ulink url="FAQ.htm">FAQs</ulink></para>
|
|
</listitem>
|
|
</itemizedlist>
|
|
</section>
|
|
|
|
<section>
|
|
<title>Getting Started</title>
|
|
|
|
<para>If you are new to Shorewall, please read these two articles
|
|
first.</para>
|
|
|
|
<itemizedlist>
|
|
<listitem>
|
|
<para><ulink url="Introduction.html">Introduction to
|
|
Shorewall</ulink></para>
|
|
</listitem>
|
|
|
|
<listitem>
|
|
<para><ulink url="shorewall_quickstart_guide.htm">QuickStart Guides
|
|
(HOWTOs)</ulink></para>
|
|
</listitem>
|
|
</itemizedlist>
|
|
|
|
<para>The following article is also recommended reading for
|
|
newcomers.</para>
|
|
|
|
<itemizedlist>
|
|
<listitem>
|
|
<para><ulink url="configuration_file_basics.htm">Configuration File
|
|
Basics</ulink><blockquote>
|
|
<para><informaltable frame="none">
|
|
<tgroup cols="2">
|
|
<tbody valign="middle">
|
|
<row>
|
|
<entry><ulink
|
|
url="configuration_file_basics.htm#Comments">Comments in
|
|
configuration files</ulink></entry>
|
|
|
|
<entry><ulink
|
|
url="configuration_file_basics.htm#Variables">Using
|
|
Shell Variables</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink
|
|
url="configuration_file_basics.htm#COMMENT">Attach
|
|
Comment to Netfilter Rules</ulink></entry>
|
|
|
|
<entry><ulink
|
|
url="configuration_file_basics.htm#dnsnames">Using DNS
|
|
Names</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink
|
|
url="configuration_file_basics.htm#Continuation">Line
|
|
Continuation</ulink></entry>
|
|
|
|
<entry><ulink
|
|
url="configuration_file_basics.htm#Compliment">Complementing
|
|
an IP address or Subnet</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink
|
|
url="configuration_file_basics.htm#INCLUDE">INCLUDE
|
|
Directive</ulink></entry>
|
|
|
|
<entry><ulink
|
|
url="configuration_file_basics.htm#IPRanges">IP Address
|
|
Ranges</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink
|
|
url="configuration_file_basics.htm#Ports">Port
|
|
Numbers/Service Names</ulink></entry>
|
|
|
|
<entry><ulink
|
|
url="configuration_file_basics.htm#Levels">Shorewall
|
|
Configurations (making a test
|
|
configuration)</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink
|
|
url="configuration_file_basics.htm#Ranges">Port
|
|
Ranges</ulink></entry>
|
|
|
|
<entry><ulink
|
|
url="configuration_file_basics.htm#MAC">Using MAC
|
|
Addresses in Shorewall</ulink></entry>
|
|
</row>
|
|
</tbody>
|
|
</tgroup>
|
|
</informaltable></para>
|
|
</blockquote></para>
|
|
</listitem>
|
|
</itemizedlist>
|
|
</section>
|
|
|
|
<section>
|
|
<title>Index to the Articles</title>
|
|
|
|
<para>The remainder of the Documentation supplements the QuickStart
|
|
Guides. Please review the appropriate guide before trying to use this
|
|
documentation directly.</para>
|
|
|
|
<informaltable frame="none">
|
|
<tgroup align="left" cols="3">
|
|
<tbody>
|
|
<row>
|
|
<entry><ulink url="Kernel2.6.html">2.6 Kernel</ulink></entry>
|
|
|
|
<entry><ulink url="IPSEC-2.6.html">IPSEC using Kernel 2.6 and
|
|
Shorewall 2.1 or Later</ulink></entry>
|
|
|
|
<entry><ulink url="Multiple_Zones.html">Routing on One
|
|
Interface</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="Accounting.html">Accounting</ulink></entry>
|
|
|
|
<entry><ulink url="ipsets.html">Ipsets</ulink></entry>
|
|
|
|
<entry><ulink url="samba.htm">Samba</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="Actions.html">Actions</ulink></entry>
|
|
|
|
<entry><ulink url="Shorewall_and_Kazaa.html">Kazaa
|
|
Filtering</ulink></entry>
|
|
|
|
<entry><ulink url="ScalabilityAndPerformance.html">Scalability and
|
|
Performance</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="Shorewall_and_Aliased_Interfaces.html">Aliased
|
|
(virtual) Interfaces (e.g., eth0:0)</ulink></entry>
|
|
|
|
<entry><ulink url="kernel.htm">Kernel
|
|
Configuration</ulink></entry>
|
|
|
|
<entry><ulink url="CompiledPrograms.html#Lite">Shorewall
|
|
Lite</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="traffic_shaping.htm">Bandwidth
|
|
Control</ulink></entry>
|
|
|
|
<entry><ulink url="PortKnocking.html#Limit">Limiting per-IPaddress
|
|
Connection Rate</ulink></entry>
|
|
|
|
<entry><ulink url="Modularization.html">Shorewall
|
|
Modularization</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink
|
|
url="blacklisting_support.htm">Blacklisting</ulink></entry>
|
|
|
|
<entry><ulink url="shorewall_logging.html">Logging</ulink></entry>
|
|
|
|
<entry><ulink url="shorewall_setup_guide.htm">Shorewall Setup
|
|
Guide</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry>Bridge: <ulink url="bridge.html">With physdev match
|
|
support</ulink></entry>
|
|
|
|
<entry><ulink url="Macros.html">Macros</ulink></entry>
|
|
|
|
<entry><ulink url="samba.htm">SMB</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry>Bridge: <ulink url="NewBridge.html">Without physdev match
|
|
support</ulink></entry>
|
|
|
|
<entry><ulink url="MAC_Validation.html">MAC
|
|
Verification</ulink></entry>
|
|
|
|
<entry><ulink url="Shorewall_Squid_Usage.html">Squid with
|
|
Shorewall</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry>Bridge: <ulink url="SimpleBridge.html">No control of
|
|
traffic through the bridge</ulink></entry>
|
|
|
|
<entry><ulink url="MultiISP.html">Multiple Internet Connections
|
|
from a Single Firewall</ulink></entry>
|
|
|
|
<entry><ulink
|
|
url="starting_and_stopping_shorewall.htm">Starting/stopping the
|
|
Firewall</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink
|
|
url="starting_and_stopping_shorewall.htm">Commands</ulink></entry>
|
|
|
|
<entry><ulink url="Multiple_Zones.html">Multiple Zones Through One
|
|
Interface</ulink></entry>
|
|
|
|
<entry><ulink url="NAT.htm">Static (one-to-one)
|
|
NAT</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="CompiledPrograms.html">Compiled Firewall
|
|
Programs</ulink></entry>
|
|
|
|
<entry><ulink url="XenMyWay-Routed.html">My Shorewall
|
|
Configuration</ulink></entry>
|
|
|
|
<entry><ulink url="support.htm">Support</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="Documentation.htm">Configuration File Reference
|
|
Manual</ulink></entry>
|
|
|
|
<entry><ulink url="NetfilterOverview.html">Netfilter
|
|
Overview</ulink></entry>
|
|
|
|
<entry><ulink url="Accounting.html">Traffic
|
|
Accounting</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="CorpNetwork.htm">Corporate Network
|
|
Example</ulink></entry>
|
|
|
|
<entry><ulink url="netmap.html">Network Mapping</ulink></entry>
|
|
|
|
<entry><ulink url="traffic_shaping.htm">Traffic
|
|
Shaping/QOS</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="dhcp.htm">DHCP</ulink></entry>
|
|
|
|
<entry><ulink url="NAT.htm">One-to-one NAT</ulink> (Static
|
|
NAT)</entry>
|
|
|
|
<entry><ulink
|
|
url="troubleshoot.htm">Troubleshooting</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="ECN.html">ECN Disabling by host or
|
|
subnet</ulink></entry>
|
|
|
|
<entry><ulink url="OPENVPN.html">OpenVPN</ulink></entry>
|
|
|
|
<entry><ulink url="UPnP.html">UPnP</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="ErrorMessages.html">Error
|
|
Messages</ulink></entry>
|
|
|
|
<entry><ulink url="starting_and_stopping_shorewall.htm">Operating
|
|
Shorewall</ulink></entry>
|
|
|
|
<entry><ulink url="upgrade_issues.htm">Upgrade
|
|
Issues</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="shorewall_extension_scripts.htm">Extension
|
|
Scripts</ulink> (User Exits)</entry>
|
|
|
|
<entry><ulink url="PacketMarking.html">Packet
|
|
Marking</ulink></entry>
|
|
|
|
<entry><ulink url="VPNBasics.html">VPN</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink
|
|
url="fallback.htm">Fallback/Uninstall</ulink></entry>
|
|
|
|
<entry><ulink url="PacketHandling.html">Packet Processing in a
|
|
Shorewall-based Firewall</ulink></entry>
|
|
|
|
<entry><ulink url="whitelisting_under_shorewall.htm">White List
|
|
Creation</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="FAQ.htm">FAQs</ulink></entry>
|
|
|
|
<entry><ulink url="ping.html">'Ping' Management</ulink></entry>
|
|
|
|
<entry><ulink url="XenMyWay.html">Xen - Shorewall in a Bridged Xen
|
|
DomU</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink
|
|
url="shorewall_features.htm">Features</ulink></entry>
|
|
|
|
<entry><ulink url="ports.htm">Port Information</ulink></entry>
|
|
|
|
<entry><ulink url="Xen.html">Xen - Shorewall in Bridged Xen
|
|
Dom0</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="Multiple_Zones.html">Forwarding Traffic on the
|
|
Same Interface</ulink></entry>
|
|
|
|
<entry><ulink url="PortKnocking.html">Port Knocking and Other Uses
|
|
of the 'Recent Match'</ulink></entry>
|
|
|
|
<entry><ulink url="XenMyWay-Routed.html">Xen - Shorewall in Routed
|
|
Xen Dom0</ulink></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="FTP.html">FTP and Shorewall</ulink></entry>
|
|
|
|
<entry><ulink url="PPTP.htm">PPTP</ulink></entry>
|
|
|
|
<entry></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="support.htm">Getting help or answers to
|
|
questions</ulink></entry>
|
|
|
|
<entry><ulink url="ProxyARP.htm">Proxy ARP</ulink></entry>
|
|
|
|
<entry></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink
|
|
url="Install.htm">Installation/Upgrade</ulink></entry>
|
|
|
|
<entry><ulink url="ReleaseModel.html">Release
|
|
Model</ulink></entry>
|
|
|
|
<entry></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="IPP2P.html">IPP2P</ulink></entry>
|
|
|
|
<entry><ulink
|
|
url="shorewall_prerequisites.htm">Requirements</ulink></entry>
|
|
|
|
<entry></entry>
|
|
</row>
|
|
|
|
<row>
|
|
<entry><ulink url="IPSEC.htm">IPSEC</ulink></entry>
|
|
|
|
<entry><ulink url="Shorewall_and_Routing.html">Routing and
|
|
Shorewall</ulink></entry>
|
|
|
|
<entry></entry>
|
|
</row>
|
|
</tbody>
|
|
</tgroup>
|
|
</informaltable>
|
|
</section>
|
|
</article> |