On 6/4/2016 10:24 AM, Filippo Carletti wrote: > Hi, > I'd like to have an "official" option to use NFQUEUE(bypass) in the > policy file like in the rules file (after 4.6.10). > Now, I'm using a custom action called NFQBY and > loc net ACCEPT:NFQBY > in policy. > See https://sourceforge.net/p/shorewall/mailman/message/32941341/ for > the whole story. > > More background: moving to shorewall 5, I'd like to take advantage of > some new features and syntax changes, to have a "cleaner" > configuration. > In rules, I'm now using NFQUEUE(bypass) instead of NFQBY, but I can't > remove the custom action from policy. > > Am I completely off track or did I miss some syntax options? > I can live with the NFQBY action. :-) > > I'm looking at this commit with the idea of allowing bypass in policy: > https://sourceforge.net/p/shorewall/code/ci/267637f13984fea2b92bd7303dee3ada0fd46bab/ > >
I think that your NFQBY action is the correct solution. As you are doing, it is necessary to specify a fallback action (ACCEPT in your example) when --bypass is given. -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------ What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic patterns at an interface-level. Reveals which users, apps, and protocols are consuming the most bandwidth. Provides multi-vendor support for NetFlow, J-Flow, sFlow and other flows. Make informed decisions using capacity planning reports. https://ad.doubleclick.net/ddm/clk/305295220;132659582;e
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
