* Nathan Gibbs wrote:
> * Nathan Gibbs wrote:
>> * Tom Eastep wrote:
>>
>>> Why don't you just put the REDIRECT rule before the DROP rule?
>>>
>> So I could put that into a macro and call that instead of DROP on my rules.
>>
> 
> My rules would look like this
> 
> DropFinal     net:10.0.0.0/8  fw      all     # Bogon
> 
> My /usr/share/shorewall/macro.DropFinal File is currently.
> 
> REDIRECT      -       81      tcp     80
> DROP          -       fw      all
> 
> Shorewall still won't fly.
> 
> I know I'm missing something simple here.
> :-)

OK, I "think" I've got it.

Rules need to look like this
DropFinal       net:10.0.0.0/8  -       -       # Bogon

My /usr/share/shorewall/macro.DropFinal File is currently.
REDIRECT-       -       81      tcp     80
DROP            -       fw      all

I have an
ACCEPT  net     fw      tcp     81
Rule before the DropFinal rules so I think I can get away with a REDIRECT-
instead of just REDIRECT

Thanks, and let me know if I am still missing something.
:-)

-- 
Sincerely,

Nathan Gibbs

Systems Administrator
Christ Media
http://www.cmpublishers.com


Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Oracle to DB2 Conversion Guide: Learn learn about native support for PL/SQL,
new data types, scalar functions, improved concurrency, built-in packages, 
OCI, SQL*Plus, data movement tools, best practices and more.
http://p.sf.net/sfu/oracle-sfdev2dev 
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to