forked from extern/shorewall_code
A couple of doc/manpage updates
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@7012 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
This commit is contained in:
parent
93f2520ccf
commit
778c39aaff
@ -495,11 +495,12 @@ OMAK=<IP address at our second home>
|
||||
|
||||
<programlisting>echo 1 > /proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_be_liberal</programlisting>
|
||||
|
||||
<para><filename>/etc/shorewall/interfaces</filename>:</para>
|
||||
<para><filename>/etc/shorewall/interfaces</filename> (don't specify
|
||||
the BROADCAST addresses if you are using Shorewall-perl):</para>
|
||||
|
||||
<programlisting>#ZONE INTERFACE BROADCAST OPTIONS
|
||||
net $EXT_IF 206.124.146.255 dhcp,norfc1918,logmartians,blacklist,tcpflags,nosmurfs
|
||||
dmz $DMZ_IF 192.168.0.255 logmartians
|
||||
dmz $DMZ_IF 206.124.146.255 logmartians
|
||||
loc $INT_IF 192.168.1.255 dhcp,routeback,logmartians
|
||||
loc $TEST_IF -
|
||||
wifi $WIFI_IF 192.168.3.255 dhcp,maclist
|
||||
@ -521,7 +522,7 @@ vpn tun+ -
|
||||
rule before the SNAT rules generated by entries in
|
||||
<filename>/etc/shorewall/nat</filename> above.</para>
|
||||
|
||||
<programlisting>#INTERFACE SUBNET ADDRESS PROTO PORT(S) IPSEC
|
||||
<programlisting>#INTERFACE SOURCE ADDRESS PROTO PORT(S) IPSEC
|
||||
+$EXT_IF:192.168.1.1 0.0.0.0/0 192.168.1.254
|
||||
$EXT_IF 192.168.0.0/22 206.124.146.179
|
||||
#LAST LINE -- ADD YOUR ENTRIES ABOVE THIS LINE -- DO NOT REMOVE</programlisting>
|
||||
|
@ -28,13 +28,13 @@
|
||||
<variablelist>
|
||||
<varlistentry>
|
||||
<term><emphasis role="bold">SOURCE</emphasis> -
|
||||
{<emphasis>all</emphasis>[<emphasis
|
||||
{<emphasis>zone</emphasis>[<emphasis
|
||||
role="bold">:</emphasis><emphasis>address</emphasis>]|<emphasis
|
||||
role="bold">all</emphasis>|<emphasis role="bold">$FW</emphasis>}
|
||||
(Shorewall-shell)</term>
|
||||
|
||||
<listitem>
|
||||
<para>Name of a zone declared in <ulink
|
||||
<para>Name of a <replaceable>zone</replaceable> declared in <ulink
|
||||
url="shorewall-zones.html">shorewall-zones</ulink>(5), <emphasis
|
||||
role="bold">all</emphasis> or <emphasis
|
||||
role="bold">$FW</emphasis>.</para>
|
||||
|
Loading…
Reference in New Issue
Block a user