I thought I had done that, but I spotted it in documentation shortly after
I sent the email and I'm not sure any more.
I'll try it tonight (hopefully!).....

Just to confirm, if include rules for smdz and dmz these will work instead
of the rules for net, right?

Thanks

Gavin

PS Any way of getting the firewall to forward DHCP request across to the
other subnet, or should I use dhcp relaying??!



                                                                                       
                                                
                      Tom Eastep                                                       
                                                
                      <teastep@shorewal        To:       [EMAIL PROTECTED]  
                                                
                      l.net>                   cc:       
[EMAIL PROTECTED]                                               
                                               Subject:  Re: [leaf-user] Shorewall 
Host File construction.                             
                      07/10/2002 14:13                                                 
                                                
                                                                                       
                                                
                                                                                       
                                                






[EMAIL PROTECTED] wrote:

>
> How do I specify that the net zone is everything BUT 10.0.1.0/24 and
> 10.46.23.0/24 in hosts??
>

Put sdmz and dmz BEFORE net in the zones file then simply define net as

net   eth2:0.0.0.0/0

-Tom
--
Tom Eastep    \ Shorewall - iptables made easy
AIM: tmeastep  \ http://www.shorewall.net
ICQ: #60745924  \ [EMAIL PROTECTED]







Visit the Virgin Atlantic website for all the latest news and great
special offers - http://www.virgin.com/atlantic

This e-mail (and any attachments) may contain privileged and/or
confidential information. If you are not the intended recipient please
do not disclose, copy, distribute, disseminate or take any action in
reliance on it. If you have received this message in error please reply
and tell us and then delete all copies on your system. Any opinion on
or advice or information contained in this email is not necessarily that
of the owners or officers of this company.

Should you wish to communicate with us by e-mail, we cannot guarantee
the security of any data outside our own computer system



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
------------------------------------------------------------------------
leaf-user mailing list: [EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to