On 04/24/2013 07:56 AM, Igor Sverkos wrote:
> Hi,
> 
> 1) I created an ipset callled "blacklist"
> 
>   ipset create blacklist hash:ip family inet
> 
> 2) I added
> 
>   DROP                net:+blacklist          $FW
> 

That must be:

    BLACKLIST           net:+blacklist          $FW

if you want the BLACKLIST_LOG_LEVEL to be applied.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Try New Relic Now & We'll Send You this Cool Shirt
New Relic is the only SaaS-based application performance monitoring service 
that delivers powerful full stack analytics. Optimize and monitor your
browser, app, & servers with just a few lines of code. Try New Relic
and get this awesome Nerd Life shirt! http://p.sf.net/sfu/newrelic_d2d_apr
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to