> BTW, here's my latest incarnation.  Priority 1 is meant to be for SIP
> and 192.168.100.5 is my Nokia N82 for wifi calls.  The RTP port it
> uses seems to be random and non-configurable so I used its static IP.
> Priority 6 is meant to be a catch-all for p2p since one of my
> bittorrent clients seems to use random ports as well.
>
> 1       192.168.100.5/24  0.0.0.0/0
> 1       0.0.0.0/0       0.0.0.0/0       udp     5060
> 1       0.0.0.0/0       0.0.0.0/0       udp     8000

I'm wondering about the above 2 lines.  They're for my SIP phone
(twinkle) and I'm not sure if 5080 and 8000 should be DEST or SOURCE
ports.  Does anyone know how that works with SIP phones?  I did an
'nmap localhost' of the system running twinkle and it has all ports
closed.  Does that mean they should be DEST ports above?

- Grant


> 2       0.0.0.0/0       0.0.0.0/0       tcp     22
> 2       0.0.0.0/0       0.0.0.0/0       tcp     -       22
> 2       0.0.0.0/0       0.0.0.0/0       udp     123
> 2       0.0.0.0/0       0.0.0.0/0       icmp    echo-request,echo-reply
> 3       0.0.0.0/0       0.0.0.0/0       tcp     -     631
> 3       0.0.0.0/0       0.0.0.0/0       udp     -     631
> 4       0.0.0.0/0       0.0.0.0/0       tcp     80,443
> 4       0.0.0.0/0       0.0.0.0/0       udp     53
> 5       0.0.0.0/0       0.0.0.0/0       tcp     873
>
> eth0    1       full*5/10       full*9/10       1
> eth0    2       full*1/10       full*9/10       2
> eth0    3       full*1/10       full*9/10       3
> eth0    4       full*1/10       full*9/10       4
> eth0    5       full*1/10       full*9/10       5
> eth0    6       full*1/10       full*9/10       6       default
>
> - Grant

------------------------------------------------------------------------------
This SF.net email is sponsored by:
SourcForge Community
SourceForge wants to tell your story.
http://p.sf.net/sfu/sf-spreadtheword
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to