[Shorewall-users] New tutorial for EL7 + Shorewall 5

2016-07-01 Thread Digimer
Hello, You guys have plenty of documentation already, but I didn't see anything for a basic office-router type guide for RHEL/CentOS 7. So I wrote one: https://alteeve.ca/w/Shorewall_5_on_EL7 It is an update on an older EL5/6 + Shorewall 4 guide I had written some time ago. You are welcome t

Re: [Shorewall-users] Shorewall 4.5.15 MAC address in rules problem

2016-07-01 Thread Bill Shirley
Thank you. I think I was standing too close to the trees to see the forest. Bill On 7/1/2016 3:14 PM, Roberto C. Sánchez wrote: > >From shorewall-rules(5), DEST section: > > Restriction: MAC addresses are not allowed (this is a Netfilter > restriction). > > You can only have a MAC in the SOURCE

Re: [Shorewall-users] Shorewall 4.5.15 MAC address in rules problem

2016-07-01 Thread Roberto C . Sánchez
>From shorewall-rules(5), DEST section: Restriction: MAC addresses are not allowed (this is a Netfilter restriction). You can only have a MAC in the SOURCE column. Regards, -Roberto On Fri, Jul 01, 2016 at 01:54:08PM -0400, Bill Shirley wrote: > I can't get Shorewall to accept a MAC address in

[Shorewall-users] Shorewall 4.5.15 MAC address in rules problem

2016-07-01 Thread Bill Shirley
I can't get Shorewall to accept a MAC address in the rules file. MAC addresses work in tcrules. params: phil_laptop_mac=~00-50-b6-70-25-63 tcrules: ?COMMENT -masq- phil laptop $INET2_FWMARK2/$CONNMASK:P $phil_laptop_mac rules: DNATinetmem:$phil_laptop_mac tcp 80