Re: [Shorewall-users] Stricter "interfaces" check

2016-10-13 Thread Ob Noxious
On Thu, Oct 13, 2016 at 4:13 AM, Tom Eastep wrote: > Tom deserves to win a nobel prize for all his nice work on > > shorewall! > > > > Not at all. I just listen to users' reports and implement changes that > address their concerns. > I already said it some months ago but it doesn't hurt to repea

Re: [Shorewall-users] Stricter "interfaces" check

2016-10-12 Thread Tom Eastep
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 10/12/2016 02:27 AM, Simon Matter wrote: >> On Tue, Oct 11, 2016 at 5:49 PM, Tom Eastep >> wrote: >> >> I believe that this particular class of user blunder is best >> guarded >>> against by setting IGNOREUNKNOWNVARIABLES=No in >>> shorewall[

Re: [Shorewall-users] Stricter "interfaces" check

2016-10-12 Thread Simon Matter
> On Tue, Oct 11, 2016 at 5:49 PM, Tom Eastep wrote: > > I believe that this particular class of user blunder is best guarded >> against by setting IGNOREUNKNOWNVARIABLES=No in shorewall[6].conf, >> > > Oh dear! Is there something you didn't thought about when designing > Shorewall? :-) It really

Re: [Shorewall-users] Stricter "interfaces" check

2016-10-11 Thread Ob Noxious
On Tue, Oct 11, 2016 at 5:49 PM, Tom Eastep wrote: I believe that this particular class of user blunder is best guarded > against by setting IGNOREUNKNOWNVARIABLES=No in shorewall[6].conf, > Oh dear! Is there something you didn't thought about when designing Shorewall? :-) It really gives the im

Re: [Shorewall-users] Stricter "interfaces" check

2016-10-11 Thread Tom Eastep
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 10/10/2016 10:41 PM, Ob Noxious wrote: > Hi, > > Just a small issue I've faced. I made a typo on the "interfaces" > file, like this : > > bar ${IF_BAR} nets=(${NET_BAR}),nosmurfs,rpfilter,bridge dmz > ${IF_F00} nets=(${NET_FOO}),nosmurfs,rpfi