[Shorewall-users] Best way to block

2014-08-19 Thread Emiliano Vazquez
Hi guys. I'm reading how is the best way to block some IPs on the network to get http/https access. I will send all the traffic trough proxy and need to block those users who eliminate the proxy setting. In Shorewall Blacklist [1] says: "The use of this file is deprecated and beginning with Sh

Re: [Shorewall-users] Best way to block

2014-08-19 Thread matt darfeuille
I would say the blrules file. -Matt On 19 Aug 2014 at 8:41, Emiliano Vazquez wrote: > Hi guys. > > I'm reading how is the best way to block some IPs on the network to get > http/https access. I will send all the traffic trough proxy and need to > block those users who eliminate the proxy sett

Re: [Shorewall-users] Best way to block

2014-08-19 Thread Roberto C . Sánchez
Emiliano, Have a look at this article: http://shorewall.net/Shorewall_Squid_Usage.html You can just forcibly redirect all web traffic through squid. You can do this transparently, or you can block ports 80 and 443 and require your users to explicitly specify the proxy in their configurations.

Re: [Shorewall-users] Best way to block

2014-08-19 Thread Emiliano Vazquez
El 19/08/14 a las 09:21, Roberto C. Sánchez escibió: > Emiliano, > > Have a look at this article: > http://shorewall.net/Shorewall_Squid_Usage.html > > You can just forcibly redirect all web traffic through squid. You can do this > transparently, or you can block ports 80 and 443 and require your

[Shorewall-users] Shorewall 4.6.3

2014-08-19 Thread Tom Eastep
The Shorewall team is happy to announce the availability of Shorewall 4.6.3. Problems Corrected: 1) This release contains defect repair up through release 4.6.2.5. 2) The SAVE_IPSETS option in the Debian version of Shorewall-init now works correctly. Thomas D. New Features: 1) A new 'run

Re: [Shorewall-users] Shorewall 4.6.3

2014-08-19 Thread PGNd
On Tue, Aug 19, 2014, at 05:29 PM, Tom Eastep wrote: > The Shorewall team is happy to announce the availability of Shorewall 4.6.3. ... > 1) A new 'run' command has been implemented. This command allows you > to run an arbitrary command in the context of the generated > script. > >