On 10/10/2018 07:04 AM, Jan Bergner wrote:
> Dear shorewall-users list,
> 
> I have some virtual network interfaces due to the fact, I use
> systemd-nspawn-containers which get names containing a minus sign. (The
> scheme is basically "ve-MACHINE_NAME".)
> 
> Unfortunately, I cannot seem to find any indication on how to treat such
> an interface name in, say, a zone assignment.
> 
> In particular, I would like to have an /etc/shorewall/interfaces like this:
> 
> #ZONE    INTERFACE    BROADCAST    OPTIONS
> 
> net eth+ detect dhcp
> nspa ve-m1 detect dhcp
> nspa ve-m2 detect dhcp
> nspb ve-m3 detect dhcp
> nspb ve-m4 detect dhcp
> oth + detect dhcp
> 
> 
> However, this does not seem to be working; my interfaces end up in the
> oth-zone, as can be expected, since this is my catch-all-zone, assuming
> the ve-interfaces are not recognized, properly.)
> 
> Initially, I thought there mus be a simple way of escaping this, but I
> could not seem to find it.
> 
> Can someone give me a hint?
> 
> 
> Thanks in advance and best regards,
> 

Which Shorewall version are you using? Your interfaces file above is
FORMAT 1, which suggests that the version is quite old.

-Tom
-- 
Tom Eastep        \   Q: What do you get when you cross a mobster with
Shoreline,         \     an international standard?
Washington, USA     \ A: Someone who makes you an offer you can't
http://shorewall.org \   understand
                      \_______________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Shorewall-users mailing list
Shorewall-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to