On 3/28/2014 3:56 PM, Rich Wales wrote:
> 
>> /man shorewall-routes/
> 
> Thanks.
> 
> I initially had some trouble getting this to work -- it appears that the
> "routes" file is ignored entirely *unless* you have a "providers" file
> *and* there is at least one provider defined in the "providers" file.  I
> confirmed this by doing "shorewall -v check" and noting which files the
> debug output said were being checked.
> 
> I had assumed that I wouldn't need a "providers" file -- or that I could
> get away with an empty "providers" file -- if I specified the "main"
> routing table instead of a provider for each of my routes.  But in order
> to get Shorewall to look at my "routes" file and create the routes
> specified therein, I needed to define a provider in the "providers"
> file, even though I'm not using this provider.
> 
> This seems like a bug/misfeature w/r/t specifying routes that use "main"
> -- but at least I have a workaround for it.
> 

The problem with 'main' routes defined in Shorewall is that during
'shorewall restart', the routes are deleted then re-added; that can be
disruptive. Routes defined using your distro's net tools don't have that
issue.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to