Tweak per-IP section

This commit is contained in:
Tom Eastep 2009-11-14 11:56:37 -08:00
parent cb67513160
commit 1c1f16661f

View File

@ -1203,12 +1203,12 @@ SAVE 0.0.0.0/0 0.0.0.0/0 all - - -
traffic based on the type of traffic. This gets really awkward when
there are a large number of local IP addresses.</para>
<para>This section describes the Shorewall facility for handling that
issue. Note that it requires that you <ulink
url="Dynamic.html#xtables-addons">install xtables-addons</ulink>. So
before you try this facility, we suggest that first you add the
following OPTION to each external interface described in
/etc/shorewall/tcdevices:</para>
<para>This section describes the Shorewall facility for making this
configuration less tedious (and a lot more efficient). Note that it
requires that you <ulink url="Dynamic.html#xtables-addons">install
xtables-addons</ulink>. So before you try this facility, we suggest that
first you add the following OPTION to each external interface described
in /etc/shorewall/tcdevices:</para>
<programlisting>flow=nfct-src</programlisting>