On 05/26/2013 07:01 PM, Dash Four wrote:
>
> Tom Eastep wrote:
>> On 05/26/2013 06:12 PM, Dash Four wrote:
>>
>>> Tom Eastep wrote:
>>>
>>>> 2) A new 'local' zone TYPE has been added to /etc/shorewall[6]/zones.
>>>> A 'local' zone is similar to an 'ipv4' ('ipv6') zone, except that
>>>> rules and policies to/from a 'local' zone may only be to/from the
>>>> firewall zone, vserver zones or other 'local' zones.
>>>>
>>>>
>>> What happens if I need these "local" zones to be completely isolated? In
>>> other words, if I define "local1" and "local2" and wish to completely
>>> isolate the traffic on these 2 local zones (in other words, ask
>>> shorewall to manage traffic only in fw2local1, local12fw, fw2local2 and
>>> local22fw, but *not* local12local2 or local22local1), what then?
>>>
>>>
>>
>> Define those policies as NONE.
>>
> Right, so every time I add a local zone, then I have to manually update
> the policy file and insert NONE for every conceivable combination
> between all my other local zones? As if I am going to do that...Give me a break; I have arthritic hands and I type all day long. So buck up and use your fingers, Mr-4; because when it comes to Shorewall, my keystrokes are much more valuable than yours. -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------ Try New Relic Now & We'll Send You this Cool Shirt New Relic is the only SaaS-based application performance monitoring service that delivers powerful full stack analytics. Optimize and monitor your browser, app, & servers with just a few lines of code. Try New Relic and get this awesome Nerd Life shirt! http://p.sf.net/sfu/newrelic_d2d_may
_______________________________________________ Shorewall-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-devel
