On 03/05/2012 12:11 PM, Ed W wrote:
> 
>> In the generated firewall script, there is a function named
>> "stop_firewall()". In that function is the input passed to
>> iptables-restore when stopping the firewall. It should contain:
>>
>> *nat
>> :PREROUTING ACCEPT [0:0]
>> :OUTPUT ACCEPT [0:0]
>> :POSTROUTING ACCEPT [0:0]
>> COMMIT
>>
>> Those 5 lines should be clearing the NAT table during 'shorewall stop'.
>> Does your generated script contain those 5 lines?
>>
> 
> Hi, I don't recall the previous exact version now, I could pull it from 
> my build scripts, but it's a 4.4 around 2-4 months old.
> 
> Right now I have the following (shall I build a minimal failing case and 
> email the config?)

Be sure to send a capabilities file as well.

Thanks,
-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Try before you buy = See our experts in action!
The most comprehensive online learning library for Microsoft developers
is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3,
Metro Style Apps, more. Free future releases when you subscribe now!
http://p.sf.net/sfu/learndevnow-dev2
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to