diff --git a/docs/three-interface.xml b/docs/three-interface.xml index c870cf498..6fc9d169c 100644 --- a/docs/three-interface.xml +++ b/docs/three-interface.xml @@ -460,6 +460,12 @@ root@lists:~# against. + + Do not configure a default route on your + internal and DMZ interfaces. Your firewall should have + exactly one default route via your ISP's Router. + + The Shorewall three-interface sample configuration assumes that the @@ -1135,4 +1141,4 @@ ACCEPT net $FW tcp 80 Operating Shorewall and Shorewall Lite contains a lot of useful operational hints. - \ No newline at end of file + diff --git a/docs/two-interface.xml b/docs/two-interface.xml index a419d9daf..978b41475 100644 --- a/docs/two-interface.xml +++ b/docs/two-interface.xml @@ -418,6 +418,10 @@ root@lists:~# for all interfaces connected to the common hub/switch. Using such a setup with a production firewall is strongly recommended against. + + Do not configure a default route on your + internal interface. Your firewall should have exactly one + default route via your ISP's Router. @@ -1142,4 +1146,4 @@ eth0 wlan0 requires the rules listed in the Shorewall/Samba documentation. - \ No newline at end of file +