2004-02-14 19:06:39 +01:00
|
|
|
<?xml version="1.0" encoding="UTF-8"?>
|
|
|
|
<!DOCTYPE article PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
|
|
|
|
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd">
|
|
|
|
<article>
|
|
|
|
<!--$Id$-->
|
|
|
|
|
|
|
|
<articleinfo>
|
2007-06-23 23:20:52 +02:00
|
|
|
<title>Shorewall 4.x Documentation</title>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
|
|
|
<authorgroup>
|
|
|
|
<author>
|
|
|
|
<firstname>Tom</firstname>
|
|
|
|
|
|
|
|
<surname>Eastep</surname>
|
|
|
|
</author>
|
|
|
|
</authorgroup>
|
|
|
|
|
2006-07-07 03:04:16 +02:00
|
|
|
<pubdate><?dbtimestamp format="Y/m/d"?></pubdate>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
|
|
|
<copyright>
|
2007-02-16 00:55:20 +01:00
|
|
|
<year>2001-2007</year>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
|
|
|
<holder>Thomas M. Eastep</holder>
|
|
|
|
</copyright>
|
|
|
|
|
|
|
|
<legalnotice>
|
|
|
|
<para>Permission is granted to copy, distribute and/or modify this
|
|
|
|
document under the terms of the GNU Free Documentation License, Version
|
|
|
|
1.2 or any later version published by the Free Software Foundation; with
|
|
|
|
no Invariant Sections, with no Front-Cover, and with no Back-Cover
|
|
|
|
Texts. A copy of the license is included in the section entitled
|
2004-09-24 00:50:12 +02:00
|
|
|
<quote><ulink url="GnuCopyright.htm">GNU Free Documentation
|
|
|
|
License</ulink></quote>.</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</legalnotice>
|
|
|
|
</articleinfo>
|
|
|
|
|
2007-07-08 23:33:01 +02:00
|
|
|
<section id="Frequent">
|
2007-01-19 21:45:10 +01:00
|
|
|
<title>Frequently Used Articles</title>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-01-19 22:56:00 +01:00
|
|
|
<simplelist>
|
2007-01-30 19:12:13 +01:00
|
|
|
<member><ulink url="FAQ.htm">FAQs</ulink> (<ulink
|
|
|
|
url="FAQ_fr.html">Français</ulink>)</member>
|
2007-01-19 22:56:00 +01:00
|
|
|
|
|
|
|
<member><ulink url="GettingStarted.html">Beginner
|
|
|
|
Documentation</ulink></member>
|
|
|
|
|
2007-01-20 00:51:51 +01:00
|
|
|
<member><ulink url="troubleshoot.htm">Troubleshooting</ulink></member>
|
2007-01-19 22:56:00 +01:00
|
|
|
</simplelist>
|
2006-08-04 15:34:39 +02:00
|
|
|
</section>
|
|
|
|
|
2007-07-08 23:33:01 +02:00
|
|
|
<section id="Index">
|
2006-08-04 15:34:39 +02:00
|
|
|
<title>Index to the Articles</title>
|
|
|
|
|
2006-10-26 16:23:47 +02:00
|
|
|
<informaltable frame="none">
|
|
|
|
<tgroup align="left" cols="3">
|
2006-09-27 20:04:17 +02:00
|
|
|
<tbody>
|
|
|
|
<row>
|
2007-06-24 18:54:21 +02:00
|
|
|
<entry><ulink url="Accounting.html">Accounting</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-06-23 23:20:52 +02:00
|
|
|
<entry><ulink url="PortKnocking.html#Limit">Limiting per-IPaddress
|
|
|
|
Connection Rate</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-12-10 18:19:51 +01:00
|
|
|
<entry><ulink url="CompiledPrograms.html#Lite">Shorewall
|
|
|
|
Lite</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="Actions.html">Actions</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-06-23 23:20:52 +02:00
|
|
|
<entry><ulink url="shorewall_logging.html">Logging</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-12-19 00:59:27 +01:00
|
|
|
<entry><ulink url="Modularization.html">Shorewall
|
|
|
|
Modularization</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="Shorewall_and_Aliased_Interfaces.html">Aliased
|
|
|
|
(virtual) Interfaces (e.g., eth0:0)</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-06-23 23:20:52 +02:00
|
|
|
<entry><ulink url="Macros.html">Macros</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="Shorewall-perl.html">Shorewall
|
|
|
|
Perl</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="Anatomy.html">Anatomy of
|
|
|
|
Shorewall</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-06-23 23:20:52 +02:00
|
|
|
<entry><ulink url="MAC_Validation.html">MAC
|
|
|
|
Verification</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="shorewall_setup_guide.htm">Shorewall Setup
|
|
|
|
Guide</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="traffic_shaping.htm">Bandwidth Control</ulink>
|
|
|
|
(<ulink url="traffic_shaping_ru.html">Russian</ulink>)</entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-07-08 23:33:01 +02:00
|
|
|
<entry><ulink url="Manpages.html">Man Pages</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="samba.htm">SMB</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="blacklisting_support.htm">Blacklisting</ulink>
|
|
|
|
(<ulink
|
|
|
|
url="blacklisting_support_ru.html">Russian</ulink>)</entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<entry><ulink url="MultiISP.html">Multiple Internet Connections
|
2007-02-02 01:04:54 +01:00
|
|
|
from a Single Firewall</ulink> (<ulink
|
|
|
|
url="MultiISP_ru.html">Russian</ulink>)</entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="Shorewall_Squid_Usage.html">Squid with
|
|
|
|
Shorewall</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry>Bridge: <ulink
|
|
|
|
url="bridge-Shorewall-perl.html">Shorewall-perl</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<entry><ulink url="Multiple_Zones.html">Multiple Zones Through One
|
|
|
|
Interface</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink
|
|
|
|
url="starting_and_stopping_shorewall.htm">Starting/stopping the
|
|
|
|
Firewall</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry>Bridge: <ulink url="SimpleBridge.html">No control of
|
|
|
|
traffic through the bridge</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-10-26 17:23:39 +02:00
|
|
|
<entry><ulink url="XenMyWay-Routed.html">My Shorewall
|
2006-09-27 20:04:17 +02:00
|
|
|
Configuration</ulink></entry>
|
2006-09-05 00:36:14 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="NAT.htm">Static (one-to-one)
|
|
|
|
NAT</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink
|
|
|
|
url="starting_and_stopping_shorewall.htm">Commands</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<entry><ulink url="NetfilterOverview.html">Netfilter
|
|
|
|
Overview</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="support.htm">Support</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="CompiledPrograms.html">Compiled Firewall
|
|
|
|
Programs</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<entry><ulink url="netmap.html">Network Mapping</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="Accounting.html">Traffic
|
|
|
|
Accounting</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="configuration_file_basics.htm">Configuration
|
|
|
|
File Basics</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<entry><ulink url="NAT.htm">One-to-one NAT</ulink> (Static
|
|
|
|
NAT)</entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="traffic_shaping.htm">Traffic
|
|
|
|
Shaping/QOS</ulink> (<ulink
|
|
|
|
url="traffic_shaping_ru.html">Russian</ulink>)</entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="dhcp.htm">DHCP</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="Multiple_Zones.html"><ulink
|
|
|
|
url="OPENVPN.html">OpenVPN</ulink></ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink
|
|
|
|
url="troubleshoot.htm">Troubleshooting</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="ECN.html">ECN Disabling by host or
|
|
|
|
subnet</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<entry><ulink url="starting_and_stopping_shorewall.htm">Operating
|
|
|
|
Shorewall</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="UPnP.html">UPnP</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="shorewall_extension_scripts.htm">Extension
|
|
|
|
Scripts</ulink> (User Exits)</entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-10-03 17:12:43 +02:00
|
|
|
<entry><ulink url="PacketMarking.html">Packet
|
|
|
|
Marking</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="upgrade_issues.htm">Upgrade
|
|
|
|
Issues</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink
|
|
|
|
url="fallback.htm">Fallback/Uninstall</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-10-03 17:12:43 +02:00
|
|
|
<entry><ulink url="PacketHandling.html">Packet Processing in a
|
|
|
|
Shorewall-based Firewall</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="VPNBasics.html">VPN</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="FAQ.htm">FAQs</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-10-03 17:12:43 +02:00
|
|
|
<entry><ulink url="ping.html">'Ping' Management</ulink></entry>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="whitelisting_under_shorewall.htm">White List
|
|
|
|
Creation</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2006-08-04 15:34:39 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink
|
|
|
|
url="shorewall_features.htm">Features</ulink></entry>
|
2004-09-24 00:50:12 +02:00
|
|
|
|
2006-10-03 17:12:43 +02:00
|
|
|
<entry><ulink url="ports.htm">Port Information</ulink></entry>
|
2005-09-17 09:33:49 +02:00
|
|
|
|
2007-04-08 19:23:26 +02:00
|
|
|
<entry><ulink url="XenMyWay.html">Xen - Shorewall in a Bridged Xen
|
|
|
|
DomU</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2005-09-17 09:33:49 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="Multiple_Zones.html">Forwarding Traffic on the
|
|
|
|
Same Interface</ulink></entry>
|
2004-09-24 00:50:12 +02:00
|
|
|
|
2006-10-03 17:12:43 +02:00
|
|
|
<entry><ulink url="PortKnocking.html">Port Knocking and Other Uses
|
|
|
|
of the 'Recent Match'</ulink></entry>
|
2004-09-24 00:50:12 +02:00
|
|
|
|
2007-07-11 21:33:45 +02:00
|
|
|
<entry><ulink url="XenMyWay-Routed.html">Xen - Shorewall in Routed
|
|
|
|
Xen Dom0</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2004-09-24 00:50:12 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="FTP.html">FTP and Shorewall</ulink></entry>
|
2004-09-24 00:50:12 +02:00
|
|
|
|
2006-10-03 17:12:43 +02:00
|
|
|
<entry><ulink url="PPTP.htm">PPTP</ulink></entry>
|
2004-09-24 00:50:12 +02:00
|
|
|
|
2007-07-11 21:33:45 +02:00
|
|
|
<entry></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
</row>
|
2004-09-24 00:50:12 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="support.htm">Getting help or answers to
|
|
|
|
questions</ulink></entry>
|
2004-09-24 00:50:12 +02:00
|
|
|
|
2006-10-03 17:12:43 +02:00
|
|
|
<entry><ulink url="ProxyARP.htm">Proxy ARP</ulink></entry>
|
2004-09-24 00:50:12 +02:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<entry></entry>
|
|
|
|
</row>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
2006-09-27 20:04:17 +02:00
|
|
|
<row>
|
2007-07-07 21:34:07 +02:00
|
|
|
<entry><ulink url="Install.htm">Installation/Upgrade</ulink>
|
|
|
|
(<ulink url="Install_fr.html">Français</ulink>)</entry>
|
2004-07-16 22:38:59 +02:00
|
|
|
|
2006-10-03 17:12:43 +02:00
|
|
|
<entry><ulink url="ReleaseModel.html">Release
|
|
|
|
Model</ulink></entry>
|
2006-09-27 20:04:17 +02:00
|
|
|
|
|
|
|
<entry></entry>
|
|
|
|
</row>
|
2007-07-07 21:34:07 +02:00
|
|
|
|
|
|
|
<row>
|
|
|
|
<entry><ulink url="IPP2P.html">IPP2P</ulink></entry>
|
|
|
|
|
|
|
|
<entry><ulink
|
|
|
|
url="shorewall_prerequisites.htm">Requirements</ulink></entry>
|
|
|
|
|
|
|
|
<entry></entry>
|
|
|
|
</row>
|
|
|
|
|
|
|
|
<row>
|
|
|
|
<entry><ulink url="IPSEC-2.6.html">IPSEC using Kernel 2.6 and
|
|
|
|
Shorewall 2.1 or Later</ulink></entry>
|
|
|
|
|
|
|
|
<entry><ulink url="Shorewall_and_Routing.html">Routing and
|
|
|
|
Shorewall</ulink></entry>
|
|
|
|
|
|
|
|
<entry></entry>
|
|
|
|
</row>
|
|
|
|
|
|
|
|
<row>
|
|
|
|
<entry><ulink url="ipsets.html">Ipsets</ulink></entry>
|
|
|
|
|
|
|
|
<entry><ulink url="Multiple_Zones.html">Routing on One
|
|
|
|
Interface</ulink></entry>
|
|
|
|
|
|
|
|
<entry></entry>
|
|
|
|
</row>
|
|
|
|
|
|
|
|
<row>
|
|
|
|
<entry><ulink url="Shorewall_and_Kazaa.html">Kazaa
|
|
|
|
Filtering</ulink></entry>
|
|
|
|
|
|
|
|
<entry><ulink url="samba.htm">Samba</ulink></entry>
|
|
|
|
|
|
|
|
<entry></entry>
|
|
|
|
</row>
|
|
|
|
|
|
|
|
<row>
|
|
|
|
<entry><ulink url="kernel.htm">Kernel
|
|
|
|
Configuration</ulink></entry>
|
|
|
|
|
|
|
|
<entry><ulink url="ScalabilityAndPerformance.html">Scalability and
|
|
|
|
Performance</ulink></entry>
|
|
|
|
|
|
|
|
<entry></entry>
|
|
|
|
</row>
|
2006-09-27 20:04:17 +02:00
|
|
|
</tbody>
|
|
|
|
</tgroup>
|
2006-10-26 16:23:47 +02:00
|
|
|
</informaltable>
|
2006-08-04 15:34:39 +02:00
|
|
|
</section>
|
2005-02-22 00:18:35 +01:00
|
|
|
</article>
|