diff --git a/docs/standalone.xml b/docs/standalone.xml index 956032785..34d6da9c5 100644 --- a/docs/standalone.xml +++ b/docs/standalone.xml @@ -102,7 +102,7 @@ Shorewall. Windows + url="http://www.sourceforge.net/projects/dos2unix">Windows Version of dos2unix @@ -119,18 +119,19 @@ Conventions Points at which configuration changes are recommended are flagged - with . + with . Configuration notes that are unique to Debian and it's derivatives are marked with . + format="GIF" />.
PPTP/ADSL - + If you have an ADSL Modem and you use PPTP to communicate with a server in that modem, you @@ -143,7 +144,7 @@
Shorewall Concepts - + The configuration files for Shorewall are contained in the directory /etc/shorewall -- for simple @@ -176,7 +177,7 @@ - If + If you installed using a Shorewall 4.x .deb, the samples are in /usr/share/doc/shorewall/examples/one-interface.. @@ -351,7 +352,7 @@ root@lists:~# the external interface. - + The Shorewall one-interface sample configuration assumes that the external interface is eth0. If @@ -459,7 +460,7 @@ root@lists:~# - + If you are running a distribution that logs Netfilter messages to a log other than /var/log/messages, then modify the @@ -499,7 +500,7 @@ root@lists:~# /usr/share/shorewall/modules then copy the file to /etc/shorewall and modify the copy. - + Modify the setting of LOAD_HELPER_ONLY as necessary.
@@ -563,7 +564,7 @@ ACCEPT net $FW tcp 143
SSH(ACCEPT) net $FW - + At this point, edit /etc/shorewall/rules to add other connections as desired. @@ -572,7 +573,7 @@ SSH(ACCEPT) net $FW
Starting and Stopping Your Firewall - + The installation procedure configures your system to start Shorewall at system boot but startup is @@ -580,7 +581,7 @@ SSH(ACCEPT) net $FW configuration is complete. Once you have completed configuration of your firewall, you must edit /etc/shorewall/shorewall.conf and set STARTUP_ENABLED=Yes. + fileref="images/openlogo-nd-25.png" /> Users of the .deb package must edit @@ -690,7 +691,7 @@ SSH(ACCEPT) net $FW systemctl disable iptables.service - + At this point, disable your existing firewall service.
diff --git a/docs/three-interface.xml b/docs/three-interface.xml index c891b2592..6f3ea2bc3 100644 --- a/docs/three-interface.xml +++ b/docs/three-interface.xml @@ -90,7 +90,7 @@ - + @@ -130,8 +130,9 @@ - Windows - Version of dos2unix + Windows Version + of dos2unix @@ -147,18 +148,19 @@ Conventions Points at which configuration changes are recommended are flagged - with . + with . Configuration notes that are unique to Debian and it's derivatives are marked with . + format="GIF" />.
PPTP/ADSL - + If you have an ADSL Modem and you use PPTP to communicate with a server in that modem, you must make the /etc/shorewall -- for simple setups, you will only need to deal with a few of these as described in this guide. - + After you have installed Shorewall, locate the three-interface Sample configuration: @@ -209,7 +211,7 @@ - If + If you installed using a Shorewall 4.x .deb, the samples are in /usr/share/doc/shorewall/examples/three-interfaces. @@ -362,7 +364,7 @@ $FW loc ACCEPT net zone even though connections are not allowed from the loc zone to the firewall itself. - + At this point, edit your /etc/shorewall/policy file and make any changes that you wish. @@ -376,7 +378,7 @@ $FW loc ACCEPT - + @@ -420,7 +422,7 @@ root@lists:~# the external interface. - + If your external interface is ppp0 or exactly one default route via your ISP's Router. - + The Shorewall three-interface sample configuration assumes that the external interface is eth0, the @@ -527,7 +529,7 @@ root@lists:~# Example sub-network - + @@ -572,7 +574,7 @@ root@lists:~# directly. To communicate with systems outside of the subnetwork, systems send packets through a gateway (router). - + Your local computers (Local Computers 1 & 2) should be configured with their default gateway set to the IP address of the @@ -595,7 +597,7 @@ root@lists:~# - + The default gateway for the DMZ computers would be @@ -651,7 +653,7 @@ root@lists:~# class="directory">/etc/shorewall/masq file. - + If your external firewall interface is eth0 then you do not need to modify the file @@ -664,7 +666,7 @@ root@lists:~# modify the SOURCE column to list just your local interface (10.10.10.0/24 in the above example). - + If your external IP is static, you can enter it in the third column in the entry if you like although your firewall will work fine if you leave that column empty. Entering your static IP in column 3 makes processing outgoing packets a little more efficient. + fileref="images/openlogo-nd-25.png" /> If you are using the Debian package, please check your shorewall.conf file to ensure that the @@ -735,7 +737,7 @@ root@lists:~# - + If you are running a distribution that logs netfilter messages to a log other than /var/log/messages, then modify the @@ -775,7 +777,7 @@ root@lists:~# /usr/share/shorewall/modules then copy the file to /etc/shorewall and modify the copy. - + Modify the setting of LOAD_HELPER_ONLY as necessary.
@@ -885,7 +887,7 @@ DNAT loc dmz:10.10.11.2 tcp 80 - $ETH0_IP - + At this point, add the DNAT and ACCEPT rules for your servers. @@ -923,7 +925,7 @@ DNAT loc dmz:10.10.11.2 tcp 80 - $ETH0_IP + format="GIF" /> You can configure a Caching Name Server on your firewall or in your DMZ. Red Hat has @@ -1025,7 +1027,7 @@ ACCEPT net $FW udp 53 SSH(ACCEPT) net $FW - Bering + Bering users will want to add the following two rules to be compatible with Jacques's Shorewall configuration: #ACTION SOURCE DEST PROTO DEST PORT(S) ACCEPT loc $FW udp 53 @@ -1038,7 +1040,7 @@ ACCEPT net $FW tcp 80 Entry 2 allows the weblet to work.
+ format="GIF" /> Now modify /etc/shorewall/rules to add or remove other connections as required. @@ -1103,7 +1105,7 @@ ACCEPT net $FW tcp 80 Starting and Stopping Your Firewall - + The installation procedure configures your system to start Shorewall at system boot but startup is @@ -1112,7 +1114,7 @@ ACCEPT net $FW tcp 80 /etc/shorewall/shorewall.conf and setting STARTUP_ENABLED=Yes. + fileref="images/openlogo-nd-25.png" /> Users of the .deb package must edit /etc/default/shorewall and set startup=1. @@ -1133,7 +1135,7 @@ ACCEPT net $FW tcp 80 shorewall clear. - + The three-interface sample assumes that you want to enable routing to/from eth1 (your local network) @@ -1220,7 +1222,7 @@ ACCEPT net $FW tcp 80 systemctl disable iptables.service - + At this point, disable your existing firewall service. diff --git a/docs/two-interface.xml b/docs/two-interface.xml index e5b29197d..870b05b91 100644 --- a/docs/two-interface.xml +++ b/docs/two-interface.xml @@ -74,7 +74,7 @@ - + @@ -88,7 +88,7 @@ Shorewall. Windows + url="http://www.sourceforge.net/projects/dos2unix">Windows Version of dos2unix @@ -121,18 +121,19 @@ Conventions Points at which configuration changes are recommended are flagged - with . + with . Configuration notes that are unique to Debian and it's derivatives are marked with . + format="GIF" />.
PPTP/ADSL - + If you have an ADSL Modem and you use PPTP to communicate with a server in that modem, you @@ -145,7 +146,7 @@
Shorewall Concepts - + The configuration files for Shorewall are contained in the directory /etc/shorewall -- for simple @@ -153,7 +154,7 @@ this guide. + format="GIF" /> After you have installed Shorewall, locate the two-interfaces samples: @@ -189,7 +190,7 @@ If you installed using a + fileref="images/openlogo-nd-25.png" />If you installed using a Shorewall 4.x .deb, the samples are in /usr/share/doc/shorewall-common/examples/two-interfaces. @@ -336,7 +337,7 @@ $FW net ACCEPT The above policy will: loc $FW ACCEPT $FW loc ACCEPT - + At this point, edit your /etc/shorewall/policy @@ -348,7 +349,7 @@ $FW loc ACCEPT - + @@ -392,7 +393,7 @@ root@lists:~# the external interface. - + If your external interface is ppp0 or internal interface. Your firewall should have exactly one default route via your ISP's Router. + format="GIF" /> The Shorewall two-interface sample configuration assumes that the external interface is eth0 and the @@ -532,7 +533,7 @@ root@lists:~# directly. To communicate with systems outside of the subnetwork, systems send packets through a gateway (router). - + Your local computers (computer 1 and computer 2 in the above diagram) should be configured with their default gateway to be the @@ -549,7 +550,7 @@ root@lists:~# The remainder of this guide will assume that you have configured your network as shown here: - + The default gateway for computer's 1 & 2 would be 10.10.10.254. @@ -606,7 +607,7 @@ root@lists:~# IP is dynamic and SNAT if the IP is static. - + If your external firewall interface is eth0, you do not need to modify the file @@ -615,7 +616,7 @@ root@lists:~# class="directory">/etc/shorewall/masq and change the first column to the name of your external interface. - + If your external IP is static, you can enter it in the third column in the column 3 (SNAT) makes the processing of outgoing packets a little more efficient. - + If you are using the Debian package, please check your shorewall.conf file to ensure that the @@ -688,7 +689,7 @@ root@lists:~# - + If you are running a distribution that logs netfilter messages to a log other than /var/log/messages, then modify the @@ -728,7 +729,7 @@ root@lists:~# /usr/share/shorewall/modules then copy the file to /etc/shorewall and modify the copy. - + Modify the setting of LOAD_HELPER_ONLY as necessary.
@@ -826,7 +827,7 @@ FTP(DNAT) net loc:10.10.10.1 For DNAT net loc:10.10.10.2:80 tcp 5000
+ format="GIF" /> At this point, modify /etc/shorewall/rules to @@ -874,7 +875,7 @@ DNAT net loc:10.10.10.2:80 tcp 5000 - You can configure a + You can configure a Caching Name Server on your firewall. Red Hat has an RPM for a caching name server (the RPM also requires the @@ -953,11 +954,11 @@ Web(ACCEPT) loc $FW Those two rules would of #ACTION SOURCE DEST PROTO DEST PORT(S) SSH(ACCEPT) net $FW Bering users will want to add the following two rules to be + format="GIF" />Bering users will want to add the following two rules to be compatible with Jacques's Shorewall configuration.#ACTION SOURCE DEST PROTO DEST PORT(S) ACCEPT loc $FW udp 53 #Allow DNS Cache to work ACCEPT loc $FW tcp 80 #Allow Weblet to work - + Now edit your /etc/shorewall/rules @@ -1023,7 +1024,7 @@ ACCEPT loc $FW tcp 80 #Allow Weblet to work Starting and Stopping Your Firewall - + The installation procedure configures your system to start Shorewall at system boot but startup is @@ -1031,7 +1032,7 @@ ACCEPT loc $FW tcp 80 #Allow Weblet to work + fileref="images/openlogo-nd-25.png" /> Users of the .deb package must edit /etc/default/shorewall and set startup=1. @@ -1051,7 +1052,7 @@ ACCEPT loc $FW tcp 80 #Allow Weblet to workshorewall clear. - + The two-interface sample assumes that you want to enable routing to/from eth1 (the local network) @@ -1137,7 +1138,7 @@ ACCEPT loc $FW tcp 80 #Allow Weblet to worksystemctl disable iptables.service - + At this point, disable your existing firewall service.
@@ -1181,9 +1182,9 @@ ACCEPT loc $FW tcp 80 #Allow Weblet to work Your new network will look similar to what is shown in the following - figure. + figure. - + The first thing to note is that the computers in your wireless network will be in a different subnet from those on your wired local LAN. @@ -1196,7 +1197,7 @@ ACCEPT loc $FW tcp 80 #Allow Weblet to work - + There are only two changes that need to be made to the Shorewall configuration: