>If you have added the 'dhcp' option to eth0 and are still seeing dhcp
>blocked, please forward the output of 'shorewall dump' as an attachment.
>You can send it to me privately if you like.
>
>Thanks,


The dhcp works flawlessy, no problem with that.
I just would like to add custom rules to permit firewall access on 
custom ports but the rule I created (the one on port 9999) is after the 
eth0_mac chain so I won't match ....
the dhcp rules instead is working and it's in the right position.

I would like to have my rule before the eth0_mac chain

follow the actual loc2fw table:

Chain loc2fw (1 references)
  pkts bytes target     prot opt in     out     source destination
    94 14460 dynamic    all  --  *      *       0.0.0.0/0 
0.0.0.0/0           ctstate INVALID,NEW,UNTRACKED
    94 14460 smurfs     all  --  *      *       0.0.0.0/0 
0.0.0.0/0           ctstate INVALID,NEW,UNTRACKED policy match dir in 
pol none
    12  4296 ACCEPT     udp  --  *      *       0.0.0.0/0 
0.0.0.0/0           udp dpts:67:68
   477 38075 tcpflags   tcp  --  *      *       0.0.0.0/0 
0.0.0.0/0           policy match dir in pol none
    82 10164 eth0_mac   all  --  *      *       0.0.0.0/0 
0.0.0.0/0           ctstate NEW,UNTRACKED policy match dir in pol none
   489 39450 ACCEPT     all  --  *      *       0.0.0.0/0 
0.0.0.0/0           ctstate RELATED,ESTABLISHED
     0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0 
0.0.0.0/0           tcp dpt:9999

Many thanks

------------------------------------------------------------------------------
Monitor Your Dynamic Infrastructure at Any Scale With Datadog!
Get real-time metrics from all of your servers, apps and tools
in one place.
SourceForge users - Click here to start your Free Trial of Datadog now!
http://pubads.g.doubleclick.net/gampad/clk?id=241902991&iu=/4140
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to