On 9/13/2014 10:24 AM, Kenneth Jacker wrote:
> Good day!
> 
> I just wanted to check with the list that, in fact, there is no way to
> have an IP address change during Shorewall's "run time".
> 
> My "params" file currently contains something like this:
> 
>      DESKTOP=`dig +short desktop.mynetgear.com`
> 
> (I know that Tom discourages using domain names in the Shorewall files.
> But for the above to work, I must use NETGEAR's name.  I can't use a
> numeric address, because I don't know what it might be!)
> 
> Here's what I found in the ML archives:
> 
>      *  On Thu, 2003-10-09 at 08:11, niels at wxn.nl wrote:
>      
>        > But when the IP adress of this dynamic hostname updates to a
>        > new address it doesn't work anymore the only way to let it work
>        > with an updated hostname seems to be a "shorewall restart"
>        > 
>        > Is there any solution to let shorewall update this without
>        > having to restart the firewall?
>        > 
>        
>        No. See http://shorewall.net/configuration_file_basics.htm#dnsnames
>        
>        -Tom
>        
> I followed the above link.  At first I thought that maybe Shorewall
> "address variables" might "do the trick", but I don't think so ...
> 
> Again, I don't think I can do this with Shorewall based on my
> "research".  But before I give up, I thought I'd check with other
> Shorewall users.
> 

"address variables" can help, but a restart is still required. Setting
AUTOMAKE=Yes will result in a faster restart by eliminating the need for
compilation.

> As always, thanks to Tom for a great system!

You're most welcome, Kenneth.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Want excitement?
Manually upgrade your production database.
When you want reliability, choose Perforce
Perforce version control. Predictably reliable.
http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to