From 3a362a70049c7aba9e1e906b06424bebae168b22 Mon Sep 17 00:00:00 2001 From: Tom Eastep Date: Wed, 25 Apr 2012 09:44:24 -0700 Subject: [PATCH] Update FAQ 17 Signed-off-by: Tom Eastep --- docs/FAQ.xml | 57 +++++++++++++++++++++++++++++++++++----------------- 1 file changed, 39 insertions(+), 18 deletions(-) diff --git a/docs/FAQ.xml b/docs/FAQ.xml index 106232ab8..de39a53c0 100644 --- a/docs/FAQ.xml +++ b/docs/FAQ.xml @@ -1486,8 +1486,11 @@ teastep@ursa:~$ The first number determines the maximum log - all2zone, zone2all - or all2all + zone2all, + zone-all, + all2zone, + all-zone, all2all or + all-all You have a The first number determines the maximum log - zone12zone2 + zone12zone2 + or zone1-zone2 Either you have a The first number determines the maximum log - @source2dest + @zone12zone2 + or + @zone1-zone2 You have a policy for traffic from - source to dest that - specifies TCP connection rate limiting (value in the LIMIT:BURST - column). The logged packet exceeds that limit and was dropped. - Note that these log messages themselves are severely rate-limited - so that a syn-flood won't generate a secondary DOS because of - excessive log message. These log messages were added in Shorewall - 2.2.0 Beta 7. + zone1 to + zone2 that specifies TCP connection + rate limiting (value in the LIMIT:BURST column). The logged packet + exceeds that limit and was dropped. Note that these log messages + themselves are severely rate-limited so that a syn-flood won't + generate a secondary DOS because of excessive log message. These + log messages were added in Shorewall 2.2.0 Beta 7. - interface_mac or - interface_rec + zone12zone2~, + zone1-zone2~ + or ~blacklistnn + + + These are the result of entries in the /etc/shorewall/blrules + file. + + + + + interface_mac or + interface_rec The packet is being logged under the The first number determines the maximum log - blacklist + blacklist The packet is being logged because the source IP is @@ -1558,7 +1579,7 @@ teastep@ursa:~$ The first number determines the maximum log - INPUT or FORWARD + INPUT or FORWARD The packet has a source IP address that isn't in any of your @@ -1585,7 +1606,7 @@ teastep@ursa:~$ The first number determines the maximum log - OUTPUT + OUTPUT The packet has a destination IP address that isn't in any of @@ -1600,7 +1621,7 @@ teastep@ursa:~$ The first number determines the maximum log - logflags + logflags The packet is being logged because it failed the checks @@ -1611,7 +1632,7 @@ teastep@ursa:~$ The first number determines the maximum log - sfilter + sfilter On systems running Shorewall 4.4.20 or later, either the