2002-10-22 20:17:48 +02:00
|
|
|
#
|
2006-10-05 02:04:59 +02:00
|
|
|
# Shorewall version 3.3 - Maclist file
|
2005-08-02 18:46:30 +02:00
|
|
|
#
|
|
|
|
# /etc/shorewall/maclist
|
2005-07-09 07:45:05 +02:00
|
|
|
#
|
|
|
|
# This file is used to define the MAC addresses and optionally their
|
|
|
|
# associated IP addresses to be allowed to use the specified interface.
|
|
|
|
# The feature is enabled by using the maclist option in the interfaces
|
|
|
|
# or hosts configuration file.
|
2002-10-22 20:17:48 +02:00
|
|
|
#
|
|
|
|
# Columns are:
|
|
|
|
#
|
2006-01-22 03:35:15 +01:00
|
|
|
# DISPOSITION ACCEPT or DROP (if MACLIST_TABLE=filter, then REJECT
|
|
|
|
# is also allowed)
|
|
|
|
#
|
2005-07-09 06:45:32 +02:00
|
|
|
# INTERFACE Network interface to a host. If the interface
|
|
|
|
# names a bridge, it may be optionally followed by
|
|
|
|
# a colon (":") and a physical port name (e.g.,
|
|
|
|
# br0:eth4).
|
2003-02-23 15:10:37 +01:00
|
|
|
#
|
2002-10-22 20:17:48 +02:00
|
|
|
# MAC MAC address of the host -- you do not need to use
|
2006-01-22 03:35:15 +01:00
|
|
|
# the Shorewall format for MAC addresses here. If IP
|
|
|
|
# ADDRESSES is supplied then MAC can be supplied as
|
|
|
|
# a dash ("-")
|
2002-10-22 20:17:48 +02:00
|
|
|
#
|
2002-10-24 02:47:43 +02:00
|
|
|
# IP ADDRESSES Optional -- if specified, both the MAC and IP address
|
|
|
|
# must match. This column can contain a comma-separated
|
2005-07-09 07:45:05 +02:00
|
|
|
# list of host and/or subnet addresses. If your kernel
|
2005-08-02 18:46:30 +02:00
|
|
|
# and iptables have iprange match support then IP
|
2005-07-09 07:45:05 +02:00
|
|
|
# address ranges are also allowed.
|
|
|
|
#
|
|
|
|
# For additional information, see http://shorewall.net/MAC_Validation.html
|
|
|
|
#
|
2005-08-02 18:46:30 +02:00
|
|
|
###############################################################################
|
2006-01-22 03:35:15 +01:00
|
|
|
#DISPOSITION INTERFACE MAC IP ADDRESSES (Optional)
|
2002-10-22 20:17:48 +02:00
|
|
|
#LAST LINE -- ADD YOUR ENTRIES ABOVE THIS LINE -- DO NOT REMOVE
|