2007-03-24 20:19:29 +01:00
|
|
|
Shorewall-pl 3.9.0
|
2007-03-24 18:16:13 +01:00
|
|
|
|
|
|
|
This companion product to Shorewall 3.4.2 and later includes a complete
|
|
|
|
rewrite of the compiler in Perl.
|
2007-03-24 01:52:30 +01:00
|
|
|
|
|
|
|
|
|
|
|
The good news:
|
|
|
|
|
|
|
|
a) The compiler is small.
|
|
|
|
b) The compiler is very fast.
|
|
|
|
c) The compiler generates a firewall script that uses iptables-restore;
|
|
|
|
so the script is very fast.
|
2007-03-24 16:59:17 +01:00
|
|
|
d) Use of the perl compiler is optional! The old slow clunky
|
2007-03-24 18:16:13 +01:00
|
|
|
Bourne-shell compiler is still available.
|
2007-03-24 01:52:30 +01:00
|
|
|
|
|
|
|
The bad news:
|
|
|
|
|
2007-03-24 18:16:13 +01:00
|
|
|
There are a number of incompatibilities between the Perl-based compiler
|
|
|
|
and the Bourne-shell one.
|
2007-03-24 01:52:30 +01:00
|
|
|
|
2007-03-24 18:16:13 +01:00
|
|
|
a) The Perl-based compiler requires the following capabilities in your
|
|
|
|
kernel and iptables.
|
2007-03-24 01:52:30 +01:00
|
|
|
|
2007-03-24 16:59:17 +01:00
|
|
|
- addrtype match
|
|
|
|
- conntrack match
|
|
|
|
- extended multiport match
|
|
|
|
|
|
|
|
These capabilities are in current distributions.
|
|
|
|
|
|
|
|
b) BRIDGING=Yes is not supported. The kernel code necessary to
|
|
|
|
support this option was removed in Linux kernel 2.6.20.
|
|
|
|
|
|
|
|
c) The BROADCAST column in the interfaces file is essentailly unused;
|
2007-03-24 01:52:30 +01:00
|
|
|
if you enter anything in this column but '-' or 'detect', you will
|
|
|
|
receive a warning.
|
|
|
|
|
2007-03-24 16:59:17 +01:00
|
|
|
d) Because the compiler is now written in Perl, your compile-time
|
2007-03-24 18:16:13 +01:00
|
|
|
extension scripts from earlier versions will no longer work.
|
2007-03-24 01:52:30 +01:00
|
|
|
|
2007-03-24 16:59:17 +01:00
|
|
|
e) The 'refresh' command is now synonamous with 'restart'.
|
2007-03-24 01:52:30 +01:00
|
|
|
|
2007-03-24 16:59:17 +01:00
|
|
|
f) Some run-time extension scripts are no longer supported because they
|
2007-03-24 01:52:30 +01:00
|
|
|
make no sense (iptables-restore instantiates the new configuration
|
|
|
|
atomically).
|
|
|
|
|
|
|
|
continue
|
|
|
|
initdone
|
|
|
|
continue
|
|
|
|
refresh
|
|
|
|
refreshed
|
|
|
|
|
2007-03-24 16:59:17 +01:00
|
|
|
g) Currently, support for ipsets is untested. That will change with
|
|
|
|
future releases but one thing is certain -- Shorewall is now out of the
|
2007-03-24 01:52:30 +01:00
|
|
|
ipset load/reload business. If the Netfilter ruleset is never cleared,
|
|
|
|
then there is no opportunity for Shorewall to load/reload your
|
|
|
|
ipsets.
|
|
|
|
|
|
|
|
So:
|
|
|
|
|
|
|
|
i) Your ipsets must be loaded before Shorewall starts.
|
|
|
|
|
|
|
|
ii) Your ipsets may not be reloaded until Shorewall is stopped or
|
|
|
|
cleared.
|
|
|
|
|
|
|
|
iii) If you specify ipsets in your routestopped file then
|
|
|
|
Shorewall must be cleared in order to reload your ipsets.
|
|
|
|
|
2007-03-24 18:16:13 +01:00
|
|
|
As a consequence, scripts generated by the Perl-based compiler will
|
|
|
|
ignore /etc/shorewall/ipsets and will issue a warning if you set
|
|
|
|
SAVE_IPSETS=Yes in shorewall.conf.
|
|
|
|
|
|
|
|
Installation
|
|
|
|
------------
|
|
|
|
|
|
|
|
1) Unpack the tarball.
|
|
|
|
|
2007-03-24 20:19:29 +01:00
|
|
|
$ tar -jxf shorewall-pl-3.9.0-1.tar.bz2
|
2007-03-24 18:16:13 +01:00
|
|
|
$ pwd
|
|
|
|
/home/teastep/shorewall/
|
|
|
|
$ ls
|
2007-03-24 20:19:29 +01:00
|
|
|
shorewall-pl-3.9.0/
|
2007-03-24 18:16:13 +01:00
|
|
|
$
|
|
|
|
|
|
|
|
2) As root, create a symbolic link to the directory containing the unpacked
|
|
|
|
files.
|
|
|
|
|
2007-03-24 20:19:29 +01:00
|
|
|
$ ln -sf /home/teastep/shorewall/ /usr/share/shorewall-pl
|
2007-03-24 01:52:30 +01:00
|
|
|
|
2007-03-24 18:16:13 +01:00
|
|
|
Using the New compiler
|
|
|
|
----------------------
|
2007-03-24 01:52:30 +01:00
|
|
|
|
2007-03-24 18:16:13 +01:00
|
|
|
By default, the old Bourne-shell based compiler will be used.
|
2007-03-24 01:52:30 +01:00
|
|
|
|
2007-03-24 18:16:13 +01:00
|
|
|
There is one change in Shorewall operation that is triggered when
|
2007-03-24 20:19:29 +01:00
|
|
|
/usr/share/shorewall-pl exists and is either a directory or a symbolic
|
2007-03-24 18:16:13 +01:00
|
|
|
link that points to a directory: Your params file will be processed
|
|
|
|
with the shell's '-a' option set which will automatically export any
|
|
|
|
variables that you set or create.
|
2007-03-24 01:52:30 +01:00
|
|
|
|
2007-03-24 18:16:13 +01:00
|
|
|
To actually use the new compiler, add this to shorewall.conf:
|
2007-03-24 01:52:30 +01:00
|
|
|
|
2007-03-24 18:16:13 +01:00
|
|
|
SHOREWALL4=Yes
|
2007-03-24 01:52:30 +01:00
|
|
|
|
2007-03-24 18:16:13 +01:00
|
|
|
If you add this setting to /etc/shorewall/shorewall.conf then by
|
|
|
|
default, the new compiler will be used on the system. If you add it to
|
|
|
|
shorewall.conf in a separate directory (such as a Shorewall-lite export
|
|
|
|
directory) then the new compiler will only be used when you compile
|
|
|
|
from that directory.
|