Re: [Shorewall-users] Parallel zones - how to block traffic from one to the other?

2008-10-31 Thread lounds
> See? You don't even have a route to 192.168.2.0/24! >> >> # cat /etc/shorewall/hosts (comments removed) >> loc eth5:192.168.168.0/24 >> loc2eth5:192.168.2.0/24 > > So the definition of loc2 is completely silly. It should be > eth5:192.168.168.13. > > Now, loc2 will be a sub-zone of loc an

Re: [Shorewall-users] Parallel zones - how to block traffic from one to the other?

2008-10-31 Thread Tom Eastep
Simon Hobson wrote: > Tom Eastep wrote: > >> Or, you can turn of NAT in your wireless router. But if you do, you need >> to update your routing on the firewall. > > Do you think : > > Turn off NAT in wireless router & put it's WAN IP on a different > subnet to the 'loc' subnet. > > would be be

[Shorewall-users] Improvements in shorewall-interfaces.man & etc.

2008-10-31 Thread PETER EASTHOPE
Tom & others, Two suggestions for small improvements in shorewall-interfaces.man. 1. Option dhcp, criterion 3., change "you have a static IP but are on a LAN segment with lots of DHCP clients." to "the interface has a static IP but is on a LAN segment with lots of DHCP cl

Re: [Shorewall-users] Improvements in shorewall-interfaces.man & etc.

2008-10-31 Thread Tom Eastep
PETER EASTHOPE wrote: > Tom & others, > > Two suggestions for small improvements in shorewall-interfaces.man. Done. Thanks, -Tom -- Tom Eastep\ The ultimate result of shielding men from the Shoreline, \ effects of folly is to fill the world with fools. Washington, USA \