forked from extern/shorewall_code
Tweak per-IP section
This commit is contained in:
parent
cb67513160
commit
1c1f16661f
@ -1203,12 +1203,12 @@ SAVE 0.0.0.0/0 0.0.0.0/0 all - - -
|
||||
traffic based on the type of traffic. This gets really awkward when
|
||||
there are a large number of local IP addresses.</para>
|
||||
|
||||
<para>This section describes the Shorewall facility for handling that
|
||||
issue. Note that it requires that you <ulink
|
||||
url="Dynamic.html#xtables-addons">install xtables-addons</ulink>. So
|
||||
before you try this facility, we suggest that first you add the
|
||||
following OPTION to each external interface described in
|
||||
/etc/shorewall/tcdevices:</para>
|
||||
<para>This section describes the Shorewall facility for making this
|
||||
configuration less tedious (and a lot more efficient). Note that it
|
||||
requires that you <ulink url="Dynamic.html#xtables-addons">install
|
||||
xtables-addons</ulink>. So before you try this facility, we suggest that
|
||||
first you add the following OPTION to each external interface described
|
||||
in /etc/shorewall/tcdevices:</para>
|
||||
|
||||
<programlisting>flow=nfct-src</programlisting>
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user