diff --git a/docs/three-interface.xml b/docs/three-interface.xml
index c870cf498..6fc9d169c 100644
--- a/docs/three-interface.xml
+++ b/docs/three-interface.xml
@@ -460,6 +460,12 @@ root@lists:~#
against.
+
+ Do not configure a default route on your
+ internal and DMZ interfaces. Your firewall should have
+ exactly one default route via your ISP's Router.
+
+
The Shorewall three-interface sample configuration assumes that the
@@ -1135,4 +1141,4 @@ ACCEPT net $FW tcp 80 Operating Shorewall and
Shorewall Lite contains a lot of useful operational hints.
-
\ No newline at end of file
+
diff --git a/docs/two-interface.xml b/docs/two-interface.xml
index a419d9daf..978b41475 100644
--- a/docs/two-interface.xml
+++ b/docs/two-interface.xml
@@ -418,6 +418,10 @@ root@lists:~#
for all interfaces connected to the common hub/switch. Using such a setup with a production firewall is strongly
recommended against.
+
+ Do not configure a default route on your
+ internal interface. Your firewall should have exactly one
+ default route via your ISP's Router.
@@ -1142,4 +1146,4 @@ eth0 wlan0
requires the rules listed in the Shorewall/Samba
documentation.
-
\ No newline at end of file
+