On 10/30/2015 03:01 PM, Ed W wrote: > On 30/10/2015 18:52, Jeremy Baker wrote: >> Can I reference an ipset that contains mac addresses only from a >> shorewall rule? > > I haven't tried, but I think it's transparent to shorewall what is in > the ipset? You simply pass it in the source/dest and the kernel does > the matching? > > Ed W > > ------------------------------------------------------------------------------ > _______________________________________________ > Shorewall-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/shorewall-users > You are correct. Using an ipset of type hash:mac works fine. Thanks -- Jeremy Baker <[email protected]> GnuPGP fingerprint = EE66 AC49 E008 E09A 7A2A 0195 50EF 580B EDBB 95B6
------------------------------------------------------------------------------ _______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
