diff --git a/manpages-lite/shorewall-lite.xml b/manpages-lite/shorewall-lite.xml index ddf7832ee..96206998b 100644 --- a/manpages-lite/shorewall-lite.xml +++ b/manpages-lite/shorewall-lite.xml @@ -263,7 +263,7 @@ + choice="req"> @@ -581,8 +581,8 @@ Restart is similar to shorewall-lite - stop followed by shorewall-lite - start. Existing connections are maintained. + start but assumes that the firewall is already started. + Existing connections are maintained. The option causes Shorewall to avoid updating the routing table(s). @@ -703,15 +703,6 @@ - - macros - - - Displays information about each macro defined on the - firewall system. - - - mangle @@ -770,7 +761,7 @@ saved configuration specified by the RESTOREFILE option in shorewall-lite.conf(5) will be restored if that saved configuration exists and has been modified - more recently than the files in /etc/shorewall. + more recently than the files in /etc/shorewall. The option causes Shorewall to avoid updating the routing table(s). diff --git a/manpages/shorewall.xml b/manpages/shorewall.xml index ad2ea2756..f4a7149da 100644 --- a/manpages/shorewall.xml +++ b/manpages/shorewall.xml @@ -1055,8 +1055,8 @@ Restart is similar to shorewall - stop followed by shorewall - start. Existing connections are maintained. If a + start except that it assumes that the firewall is already + started. Existing connections are maintained. If a directory is included in the command, Shorewall will look in that directory first for configuration files. diff --git a/manpages6-lite/shorewall6-lite.conf.xml b/manpages6-lite/shorewall6-lite.conf.xml index 31d5cfbcd..ef7e7fc83 100644 --- a/manpages6-lite/shorewall6-lite.conf.xml +++ b/manpages6-lite/shorewall6-lite.conf.xml @@ -46,12 +46,12 @@ IPTABLES=[pathname] + role="bold">IP6TABLES=[pathname] - This parameter names the iptables executable to be used by + This parameter names the ip6tables executable to be used by Shorewall6. If not specified or if specified as a null value, then - the iptables executable located using the PATH option is + the ip6tables executable located using the PATH option is used. @@ -61,8 +61,8 @@ role="bold">LOGFILE=[pathname] - This parameter tells the /sbin/shorewall6 program where to look - for Shorewall6 messages when processing the This parameter tells the /sbin/shorewall6 program where to + look for Shorewall6 messages when processing the dump, logwatch, show log, and hits commands. @@ -119,14 +119,13 @@ SHOREWALL6_SHELL=[pathname] + role="bold">SHOREWALL_SHELL=[pathname] This option is used to specify the shell program to be used to - run the Shorewall6 compiler and to interpret the compiled script. If - not specified or specified as a null value, /bin/sh is assumed. - Using a light-weight shell such as ash or dash can significantly - improve performance. + interpret the compiled script. If not specified or specified as a + null value, /bin/sh is assumed. Using a light-weight shell such as + ash or dash can significantly improve performance. @@ -137,9 +136,9 @@ This parameter should be set to the name of a file that the firewall should create if it starts successfully and remove when it - stops. Creating and removing this file allows Shorewall6 to work with - your distribution's initscripts. For RedHat, this should be set to - /var/lock/subsys/shorewall6. For Debian, the value is + stops. Creating and removing this file allows Shorewall6 to work + with your distribution's initscripts. For RedHat, this should be set + to /var/lock/subsys/shorewall6. For Debian, the value is /var/state/shorewall6 and in LEAF it is /var/run/shorwall. @@ -187,8 +186,9 @@ shorewall6-ipsec(5), shorewall6-maclist(5), shorewall6-masq(5), shorewall6-nat(5), shorewall6-netmap(5), shorewall6-params(5), shorewall6-policy(5), shorewall6-providers(5), shorewall6-proxyarp(5), - shorewall6-route_rules(5), shorewall6-routestopped(5), shorewall6-rules(5), - shorewall6-tcclasses(5), shorewall6-tcdevices(5), shorewall6-tcrules(5), - shorewall6-tos(5), shorewall6-tunnels(5), shorewall6-zones(5) + shorewall6-route_rules(5), shorewall6-routestopped(5), + shorewall6-rules(5), shorewall6-tcclasses(5), shorewall6-tcdevices(5), + shorewall6-tcrules(5), shorewall6-tos(5), shorewall6-tunnels(5), + shorewall6-zones(5) diff --git a/manpages6-lite/shorewall6-lite.xml b/manpages6-lite/shorewall6-lite.xml index 847da8e49..9f9d6b19b 100644 --- a/manpages6-lite/shorewall6-lite.xml +++ b/manpages6-lite/shorewall6-lite.xml @@ -232,7 +232,7 @@ + choice="req"> @@ -246,7 +246,7 @@ - + @@ -607,20 +607,11 @@ connections - Displays the IP connections currently being tracked by + Displays the IPv6 connections currently being tracked by the firewall. - - macros - - - Displays information about each macro defined on the - firewall system. - - - mangle @@ -634,19 +625,6 @@ - - nat - - - Displays the Netfilter nat table using the command - ip6tables -t nat -L -n -v.The - -x option is passed directly - through to iptables and causes actual packet and byte counts - to be displayed. Without this option, those counts are - abbreviated. - - - tc @@ -734,7 +712,7 @@ See ALSO http://www.shorewall.net/starting_and_stopping_shorewall6.htm + url="http://www.shorewall.net/starting_and_stopping_shorewall6.htm">http://www.shorewall.net/starting_and_stopping_shorewall.htm shorewall6-accounting(5), shorewall6-actions(5), shorewall6-blacklist(5), shorewall6-hosts(5), shorewall6-interfaces(5), diff --git a/manpages6/shorewall6.conf.xml b/manpages6/shorewall6.conf.xml index a19b80d4b..0819a9b64 100644 --- a/manpages6/shorewall6.conf.xml +++ b/manpages6/shorewall6.conf.xml @@ -545,7 +545,7 @@ net all DROP infothen the chain name is 'net2all' the ip6tables executable located using the PATH option is used. - Regardless of how the IP6TABLES utility is located (specified + Regardless of how the ip6tables utility is located (specified via IP6TABLES= or located via PATH), Shorewall6 uses the ip6tables-restore and ip6tables-save utilities from that same directory. @@ -625,7 +625,7 @@ net all DROP infothen the chain name is 'net2all' logging from the nat table's PREROUTING chain is: Shorewall:nat:PREROUTING - + To help insure that all packets in the NEW state are @@ -1096,67 +1096,6 @@ net all DROP infothen the chain name is 'net2all' - - USE_DEFAULT_RT=[Yes|No] - - - When set to 'Yes', this option causes the Shorewall6 multi-ISP - feature to create a different set of routing rules which are - resilient to changes in the main routing table. Such changes can - occur for a number of reasons, VPNs going up and down being an - example. The idea is to send packets through the main table prior to - applying any of the Shorewall6-generated routing rules. So changes - to the main table will affect the routing of packets by - default. - - When USE_DEFAULT_RT=Yes: - - - - Both the DUPLICATE and the COPY columns in providers(5) file must - remain empty (or contain "-"). - - - - The default route is added to the the 'default' table - rather than to the main table. - - - - balance is assumed unless - loose is specified. - - - - Packets are sent through the main routing table by a rule - with priority 999. In routing_rules(5), - the range 1-998 may be used for inserting rules that bypass the - main table. - - - - All provider gateways must be specified explicitly in the - GATEWAY column. detect may not - be specified. - - - - You should disable all default route management outside of - Shorewall6. If a default route is added to the main table while - Shorewall6 is started, then all policy routing will stop working - (except for those routing rules in the priority range - 1-998). - - - - If USE_DEFAULT_RT is not set or if it is set to the empty - string then USE_DEFAULT_RT=No is assumed. - - - VERBOSITY=[number] diff --git a/manpages6/shorewall6.xml b/manpages6/shorewall6.xml index adef03000..ca2721809 100644 --- a/manpages6/shorewall6.xml +++ b/manpages6/shorewall6.xml @@ -838,8 +838,8 @@ Restart is similar to shorewall6 - stop followed by shorewall6 - start. Existing connections are maintained. If a + start except that it assumes that the firewall is already + started. Existing connections are maintained. If a directory is included in the command, Shorewall6 will look in that directory first for configuration files.