forked from extern/shorewall_code
16906234c8
git-svn-id: https://shorewall.svn.sourceforge.net/svnroot/shorewall/trunk@535 fbd18981-670d-0410-9b5c-8dc0c1a9a2bb
269 lines
13 KiB
HTML
269 lines
13 KiB
HTML
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
|
||
<html>
|
||
<head>
|
||
|
||
<meta http-equiv="Content-Type"
|
||
content="text/html; charset=windows-1252">
|
||
<title>Shoreline Firewall (Shorewall) 1.4</title>
|
||
<base
|
||
target="_self">
|
||
</head>
|
||
<body>
|
||
|
||
<table border="0" cellpadding="0" cellspacing="4"
|
||
style="border-collapse: collapse;" width="100%" id="AutoNumber3"
|
||
bgcolor="#4b017c">
|
||
<tbody>
|
||
<tr>
|
||
<td
|
||
width="100%" height="90">
|
||
|
||
<h1 align="center"> <font size="4"><i> <a
|
||
href="http://www.cityofshoreline.com"> <img vspace="4" hspace="4"
|
||
alt="Shorwall Logo" height="70" width="85" align="left"
|
||
src="images/washington.jpg" border="0">
|
||
</a></i></font><a
|
||
href="http://www.shorewall.net" target="_top"><img border="1"
|
||
src="images/shorewall.jpg" width="119" height="38" hspace="4"
|
||
alt="(Shorewall Logo)" align="right" vspace="4">
|
||
</a></h1>
|
||
<small><small><small><small><a
|
||
href="http://www.shorewall.net" target="_top"> </a></small></small></small></small>
|
||
|
||
<div align="center">
|
||
<h1><font color="#ffffff"> Shorewall 1.4</font><i><font
|
||
color="#ffffff"> <small><small><small>"iptables made easy"</small></small></small></font></i><a
|
||
href="1.3" target="_top"><font color="#ffffff"><br>
|
||
<small><small><small><small>Shorewall 1.3 Site is here</small></small></small></small></font></a><a
|
||
href="http://www1.shorewall.net/1.2/index.htm"><font color="#ffffff"><br>
|
||
<small><small><small><small>Shorewall 1.2 Site is here</small></small></small></small></font></a><br>
|
||
|
||
</h1>
|
||
</div>
|
||
|
||
<p><a href="http://www.shorewall.net" target="_top"> </a> </p>
|
||
</td>
|
||
</tr>
|
||
|
||
</tbody>
|
||
</table>
|
||
|
||
<div align="center">
|
||
<center>
|
||
<table border="0" cellpadding="0" cellspacing="0"
|
||
style="border-collapse: collapse;" width="100%" id="AutoNumber4">
|
||
<tbody>
|
||
<tr>
|
||
<td
|
||
width="90%">
|
||
<h2 align="left">What is it?</h2>
|
||
|
||
<p>The Shoreline Firewall, more commonly known as "Shorewall", is
|
||
a <a href="http://www.netfilter.org">Netfilter</a> (iptables) based
|
||
firewall that can be used on a dedicated firewall system, a multi-function
|
||
gateway/router/server or on a standalone GNU/Linux system.</p>
|
||
|
||
<p>This program is free software; you can redistribute it and/or modify
|
||
it under
|
||
the terms of <a
|
||
href="http://www.gnu.org/licenses/gpl.html">Version 2 of the
|
||
GNU General Public License</a> as published by the Free Software
|
||
Foundation.<br>
|
||
<br>
|
||
This program
|
||
is distributed in the hope that it will
|
||
be useful, but WITHOUT ANY WARRANTY; without
|
||
even the implied warranty of MERCHANTABILITY
|
||
or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||
GNU General Public License for more details.<br>
|
||
<br>
|
||
You should have
|
||
received a copy of the GNU General Public
|
||
License along with this program; if
|
||
not, write to the Free Software Foundation,
|
||
Inc., 675 Mass Ave, Cambridge, MA 02139, USA</p>
|
||
|
||
<p><a href="copyright.htm">Copyright 2001, 2002, 2003 Thomas M. Eastep</a></p>
|
||
|
||
<p> <a href="http://leaf.sourceforge.net" target="_top"><img
|
||
border="0" src="images/leaflogo.gif" width="49" height="36">
|
||
</a>Jacques Nilo
|
||
and Eric Wolzak have a LEAF (router/firewall/gateway
|
||
on a floppy, CD or compact flash) distribution
|
||
called <i>Bering</i> that features
|
||
Shorewall-1.3.14 and Kernel-2.4.20. You can
|
||
find their work at: <a
|
||
href="http://leaf.sourceforge.net/devel/jnilo"> http://leaf.sourceforge.net/devel/jnilo<br>
|
||
</a></p>
|
||
|
||
<p><b>Congratulations to Jacques and Eric on the recent release of
|
||
Bering 1.1!!! </b><br>
|
||
</p>
|
||
|
||
<h2>This is a mirror of the main Shorewall web site at SourceForge
|
||
(<a href="http://shorewall.sf.net" target="_top">http://shorewall.sf.net</a>)</h2>
|
||
|
||
<h2>News</h2>
|
||
|
||
<p><b>4/12/2002 - Greater Seattle Linux Users Group Presentation </b><b><img
|
||
border="0" src="images/new10.gif" width="28" height="12" alt="(New)">
|
||
</b></p>
|
||
|
||
<blockquote>This morning, I gave <a href="GSLUG.htm" target="_top">a
|
||
Shorewall presentation to GSLUG</a>. The presentation is in HTML format
|
||
but was generated from Microsoft PowerPoint and is best viewed using Internet
|
||
Explorer although Konqueror also seems to work reasonably well. Neither Opera
|
||
or Netscape work well to view the presentation.<br>
|
||
</blockquote>
|
||
|
||
<p><b>4/9/2003 - Shorewall 1.4.2</b><b> </b><b> </b><b><img
|
||
border="0" src="images/new10.gif" width="28" height="12" alt="(New)">
|
||
</b><br>
|
||
</p>
|
||
|
||
<p><b> Problems Corrected:</b></p>
|
||
|
||
<blockquote>
|
||
<ol>
|
||
<li>TCP connection requests rejected out of the <b>common</b>
|
||
chain are now properly rejected with TCP RST; previously, some of these
|
||
requests were rejected with an ICMP port-unreachable response.</li>
|
||
<li>'traceroute -I' from behind the firewall previously timed
|
||
out on the first hop (e.g., to the firewall). This has been worked around.</li>
|
||
|
||
</ol>
|
||
</blockquote>
|
||
|
||
<p><b> New Features:</b></p>
|
||
|
||
<blockquote>
|
||
<ol>
|
||
<li>Where an entry in the/etc/shorewall/hosts file specifies
|
||
a particular host or network, Shorewall now creates an intermediate chain
|
||
for handling input from the related zone. This can substantially reduce the
|
||
number of rules traversed by connections requests from such zones.<br>
|
||
<br>
|
||
</li>
|
||
<li>Any file may include an INCLUDE directive. An INCLUDE directive
|
||
consists of the word INCLUDE followed by a file name and causes the contents
|
||
of the named file to be logically included into the file containing the INCLUDE.
|
||
File names given in an INCLUDE directive are assumed to reside in /etc/shorewall
|
||
or in an alternate configuration directory if one has been specified for
|
||
the command. <br>
|
||
<br>
|
||
Examples:<br>
|
||
shorewall/params.mgmt:<br>
|
||
MGMT_SERVERS=1.1.1.1,2.2.2.2,3.3.3.3<br>
|
||
TIME_SERVERS=4.4.4.4<br>
|
||
BACKUP_SERVERS=5.5.5.5<br>
|
||
----- end params.mgmt -----<br>
|
||
<br>
|
||
<br>
|
||
shorewall/params:<br>
|
||
# Shorewall 1.3 /etc/shorewall/params<br>
|
||
[..]<br>
|
||
#######################################<br>
|
||
<br>
|
||
INCLUDE params.mgmt <br>
|
||
<br>
|
||
# params unique to this host here<br>
|
||
#LAST LINE - ADD YOUR ENTRIES ABOVE THIS ONE - DO NOT REMOVE<br>
|
||
----- end params -----<br>
|
||
<br>
|
||
<br>
|
||
shorewall/rules.mgmt:<br>
|
||
ACCEPT net:$MGMT_SERVERS $FW tcp 22<br>
|
||
ACCEPT $FW net:$TIME_SERVERS udp 123<br>
|
||
ACCEPT $FW net:$BACKUP_SERVERS tcp 22<br>
|
||
----- end rules.mgmt -----<br>
|
||
<br>
|
||
shorewall/rules:<br>
|
||
# Shorewall version 1.3 - Rules File<br>
|
||
[..]<br>
|
||
#######################################<br>
|
||
<br>
|
||
INCLUDE rules.mgmt <br>
|
||
<br>
|
||
# rules unique to this host here<br>
|
||
#LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE<br>
|
||
----- end rules -----<br>
|
||
<br>
|
||
INCLUDE's may be nested to a level of 3 -- further nested INCLUDE directives
|
||
are ignored with a warning message.<br>
|
||
<br>
|
||
</li>
|
||
<li>Routing traffic from an interface back out that interface
|
||
continues to be a problem. While I firmly believe that this should never
|
||
happen, people continue to want to do it. To limit the damage that such
|
||
nonsense produces, I have added a new 'routeback' option in /etc/shorewall/interfaces
|
||
and /etc/shorewall/hosts. When used in /etc/shorewall/interfaces, the 'ZONE'
|
||
column may not contain '-'; in other words, 'routeback' can't be used as
|
||
an option for a multi-zone interface. The 'routeback' option CAN be specified
|
||
however on individual group entries in /etc/shorewall/hosts.<br>
|
||
<br>
|
||
The 'routeback' option is similar to the old 'multi' option with two
|
||
exceptions:<br>
|
||
<br>
|
||
a) The option pertains to a particular zone,interface,address tuple.<br>
|
||
<br>
|
||
b) The option only created infrastructure to pass traffic from (zone,interface,address)
|
||
tuples back to themselves (the 'multi' option affected all (zone,interface,address)
|
||
tuples associated with the given 'interface').<br>
|
||
<br>
|
||
See the '<a href="upgrade_issues.htm">Upgrade Issues</a>' for information
|
||
about how this new option may affect your configuration.<br>
|
||
</li>
|
||
|
||
</ol>
|
||
</blockquote>
|
||
|
||
<p><b></b></p>
|
||
|
||
<p><a href="News.htm">More News</a></p>
|
||
|
||
<h2><a name="Donations"></a>Donations</h2>
|
||
</td>
|
||
<td
|
||
width="88" bgcolor="#4b017c" valign="top" align="center"> <br>
|
||
</td>
|
||
</tr>
|
||
|
||
</tbody>
|
||
</table>
|
||
</center>
|
||
</div>
|
||
|
||
<table border="0" cellpadding="5" cellspacing="0"
|
||
style="border-collapse: collapse;" width="100%" id="AutoNumber2"
|
||
bgcolor="#4b017c">
|
||
<tbody>
|
||
<tr>
|
||
<td width="100%"
|
||
style="margin-top: 1px;">
|
||
|
||
<p align="center"><a href="http://www.starlight.org"> <img
|
||
border="4" src="images/newlog.gif" width="57" height="100" align="left"
|
||
hspace="10">
|
||
</a></p>
|
||
|
||
<p align="center"><font size="4" color="#ffffff">Shorewall is free
|
||
but if you try it and find it useful, please consider making a donation
|
||
to <a
|
||
href="http://www.starlight.org"><font color="#ffffff">Starlight Children's
|
||
Foundation.</font></a> Thanks!</font></p>
|
||
</td>
|
||
</tr>
|
||
|
||
</tbody>
|
||
</table>
|
||
|
||
<p><font size="2">Updated 4/12/2003 - <a href="support.htm">Tom Eastep</a></font>
|
||
<br>
|
||
</p>
|
||
<br>
|
||
<br>
|
||
<br>
|
||
<br>
|
||
</body>
|
||
</html>
|