<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE article PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN" "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"> <article> <!--$Id$--> <articleinfo> <title>Shorewall 3.x Documentation</title> <authorgroup> <author> <firstname>Tom</firstname> <surname>Eastep</surname> </author> </authorgroup> <pubdate><?dbtimestamp format="Y/m/d"?></pubdate> <copyright> <year>2001-2006</year> <holder>Thomas M. Eastep</holder> </copyright> <legalnotice> <para>Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation; with no Invariant Sections, with no Front-Cover, and with no Back-Cover Texts. A copy of the license is included in the section entitled <quote><ulink url="GnuCopyright.htm">GNU Free Documentation License</ulink></quote>.</para> </legalnotice> </articleinfo> <section> <title>FAQs</title> <itemizedlist> <listitem> <para><ulink url="FAQ.htm">FAQs</ulink></para> </listitem> </itemizedlist> </section> <section> <title>Getting Started</title> <para>If you are new to Shorewall, please read these two articles first.</para> <itemizedlist> <listitem> <para><ulink url="Introduction.html">Introduction to Shorewall</ulink></para> </listitem> <listitem> <para><ulink url="shorewall_quickstart_guide.htm">QuickStart Guides (HOWTOs)</ulink></para> </listitem> </itemizedlist> <para>The following article is also recommended reading for newcomers.</para> <itemizedlist> <listitem> <para><ulink url="configuration_file_basics.htm">Configuration File Basics</ulink><blockquote> <para><informaltable frame="none"> <tgroup cols="2"> <tbody valign="middle"> <row> <entry><ulink url="configuration_file_basics.htm#Comments">Comments in configuration files</ulink></entry> <entry><ulink url="configuration_file_basics.htm#Variables">Using Shell Variables</ulink></entry> </row> <row> <entry><ulink url="configuration_file_basics.htm#COMMENT">Attach Comment to Netfilter Rules</ulink></entry> <entry><ulink url="configuration_file_basics.htm#dnsnames">Using DNS Names</ulink></entry> </row> <row> <entry><ulink url="configuration_file_basics.htm#Continuation">Line Continuation</ulink></entry> <entry><ulink url="configuration_file_basics.htm#Compliment">Complementing an IP address or Subnet</ulink></entry> </row> <row> <entry><ulink url="configuration_file_basics.htm#INCLUDE">INCLUDE Directive</ulink></entry> <entry><ulink url="configuration_file_basics.htm#IPRanges">IP Address Ranges</ulink></entry> </row> <row> <entry><ulink url="configuration_file_basics.htm#Ports">Port Numbers/Service Names</ulink></entry> <entry><ulink url="configuration_file_basics.htm#Levels">Shorewall Configurations (making a test configuration)</ulink></entry> </row> <row> <entry><ulink url="configuration_file_basics.htm#Ranges">Port Ranges</ulink></entry> <entry><ulink url="configuration_file_basics.htm#MAC">Using MAC Addresses in Shorewall</ulink></entry> </row> </tbody> </tgroup> </informaltable></para> </blockquote></para> </listitem> </itemizedlist> </section> <section> <title>Index to the Articles</title> <para>The remainder of the Documentation supplements the QuickStart Guides. Please review the appropriate guide before trying to use this documentation directly.</para> <informaltable frame="none"> <tgroup align="left" cols="3"> <tbody> <row> <entry><ulink url="Kernel2.6.html">2.6 Kernel</ulink></entry> <entry><ulink url="IPSEC-2.6.html">IPSEC using Kernel 2.6 and Shorewall 2.1 or Later</ulink></entry> <entry><ulink url="Multiple_Zones.html">Routing on One Interface</ulink></entry> </row> <row> <entry><ulink url="Accounting.html">Accounting</ulink></entry> <entry><ulink url="ipsets.html">Ipsets</ulink></entry> <entry><ulink url="samba.htm">Samba</ulink></entry> </row> <row> <entry><ulink url="Actions.html">Actions</ulink></entry> <entry><ulink url="Shorewall_and_Kazaa.html">Kazaa Filtering</ulink></entry> <entry><ulink url="CompiledPrograms.html#Lite">Shorewall Lite</ulink></entry> </row> <row> <entry><ulink url="Shorewall_and_Aliased_Interfaces.html">Aliased (virtual) Interfaces (e.g., eth0:0)</ulink></entry> <entry><ulink url="kernel.htm">Kernel Configuration</ulink></entry> <entry><ulink url="shorewall_setup_guide.htm">Shorewall Setup Guide</ulink></entry> </row> <row> <entry><ulink url="traffic_shaping.htm">Bandwidth Control</ulink></entry> <entry><ulink url="PortKnocking.html#Limit">Limiting per-IPaddress Connection Rate</ulink></entry> <entry><ulink url="samba.htm">SMB</ulink></entry> </row> <row> <entry><ulink url="blacklisting_support.htm">Blacklisting</ulink></entry> <entry><ulink url="shorewall_logging.html">Logging</ulink></entry> <entry><ulink url="Shorewall_Squid_Usage.html">Squid with Shorewall</ulink></entry> </row> <row> <entry>Bridge: <ulink url="bridge.html">With physdev match support</ulink></entry> <entry><ulink url="Macros.html">Macros</ulink></entry> <entry><ulink url="starting_and_stopping_shorewall.htm">Starting/stopping the Firewall</ulink></entry> </row> <row> <entry>Bridge: <ulink url="NewBridge.html">Without physdev match support</ulink></entry> <entry><ulink url="MAC_Validation.html">MAC Verification</ulink></entry> <entry><ulink url="NAT.htm">Static (one-to-one) NAT</ulink></entry> </row> <row> <entry>Bridge: <ulink url="SimpleBridge.html">No control of traffic through the bridge</ulink></entry> <entry><ulink url="MultiISP.html">Multiple Internet Connections from a Single Firewall</ulink></entry> <entry><ulink url="support.htm">Support</ulink></entry> </row> <row> <entry><ulink url="starting_and_stopping_shorewall.htm">Commands</ulink></entry> <entry><ulink url="Multiple_Zones.html">Multiple Zones Through One Interface</ulink></entry> <entry><ulink url="Accounting.html">Traffic Accounting</ulink></entry> </row> <row> <entry><ulink url="CompiledPrograms.html">Compiled Firewall Programs</ulink></entry> <entry><ulink url="XenMyWay-Routed.html">My Shorewall Configuration</ulink></entry> <entry><ulink url="traffic_shaping.htm">Traffic Shaping/QOS</ulink></entry> </row> <row> <entry><ulink url="Documentation.htm">Configuration File Reference Manual</ulink></entry> <entry><ulink url="NetfilterOverview.html">Netfilter Overview</ulink></entry> <entry><ulink url="troubleshoot.htm">Troubleshooting</ulink></entry> </row> <row> <entry><ulink url="CorpNetwork.htm">Corporate Network Example</ulink></entry> <entry><ulink url="netmap.html">Network Mapping</ulink></entry> <entry><ulink url="UPnP.html">UPnP</ulink></entry> </row> <row> <entry><ulink url="dhcp.htm">DHCP</ulink></entry> <entry><ulink url="NAT.htm">One-to-one NAT</ulink> (Static NAT)</entry> <entry><ulink url="upgrade_issues.htm">Upgrade Issues</ulink></entry> </row> <row> <entry><ulink url="ECN.html">ECN Disabling by host or subnet</ulink></entry> <entry><ulink url="OPENVPN.html">OpenVPN</ulink></entry> <entry><ulink url="VPNBasics.html">VPN</ulink></entry> </row> <row> <entry><ulink url="ErrorMessages.html">Error Messages</ulink></entry> <entry><ulink url="starting_and_stopping_shorewall.htm">Operating Shorewall</ulink></entry> <entry><ulink url="whitelisting_under_shorewall.htm">White List Creation</ulink></entry> </row> <row> <entry><ulink url="shorewall_extension_scripts.htm">Extension Scripts</ulink> (User Exits)</entry> <entry><ulink url="PacketMarking.html">Packet Marking</ulink></entry> <entry><ulink url="XenMyWay.html">Xen - Shorewall in a Bridged Xen DomU</ulink></entry> </row> <row> <entry><ulink url="fallback.htm">Fallback/Uninstall</ulink></entry> <entry><ulink url="PacketHandling.html">Packet Processing in a Shorewall-based Firewall</ulink></entry> <entry><ulink url="Xen.html">Xen - Shorewall in Bridged Xen Dom0</ulink></entry> </row> <row> <entry><ulink url="FAQ.htm">FAQs</ulink></entry> <entry><ulink url="ping.html">'Ping' Management</ulink></entry> <entry><ulink url="XenMyWay-Routed.html">Xen - Shorewall in Routed Xen Dom0</ulink></entry> </row> <row> <entry><ulink url="shorewall_features.htm">Features</ulink></entry> <entry><ulink url="ports.htm">Port Information</ulink></entry> <entry></entry> </row> <row> <entry><ulink url="Multiple_Zones.html">Forwarding Traffic on the Same Interface</ulink></entry> <entry><ulink url="PortKnocking.html">Port Knocking and Other Uses of the 'Recent Match'</ulink></entry> <entry></entry> </row> <row> <entry><ulink url="FTP.html">FTP and Shorewall</ulink></entry> <entry><ulink url="PPTP.htm">PPTP</ulink></entry> <entry></entry> </row> <row> <entry><ulink url="support.htm">Getting help or answers to questions</ulink></entry> <entry><ulink url="ProxyARP.htm">Proxy ARP</ulink></entry> <entry></entry> </row> <row> <entry><ulink url="Install.htm">Installation/Upgrade</ulink></entry> <entry><ulink url="ReleaseModel.html">Release Model</ulink></entry> <entry></entry> </row> <row> <entry><ulink url="IPP2P.html">IPP2P</ulink></entry> <entry><ulink url="shorewall_prerequisites.htm">Requirements</ulink></entry> <entry></entry> </row> <row> <entry><ulink url="IPSEC.htm">IPSEC</ulink></entry> <entry><ulink url="Shorewall_and_Routing.html">Routing and Shorewall</ulink></entry> <entry></entry> </row> </tbody> </tgroup> </informaltable> </section> </article>