> BTW, how can I let users from outside (net) to access ( eg.
> ssh/http/https) to a VM instance running in loc zone? In the
> /etc/shorewall/policy,  net2loc is a REJECT by default.

You must use DNAT rules.

