[Shorewall-users] Ping only from known domains

2007-10-12 Thread Bart Verstraete
Hi, Got the following rule: Ping/ACCEPT net:proxy.ovh.net,proxy.p19.ovh.net,proxy.rbx.ovh.net,ping.ovh.net $FW but then everyone can ping? Or is the rule wrong? Got shorewall 3.2.6 on debian 4.0. Here are my defaullt policys: $FWnetACCEPT netallDROPinfo a

Re: [Shorewall-users] Ping only from known domains

2007-10-12 Thread Prasanna Krishnamoorthy
On 10/12/07, Bart Verstraete <[EMAIL PROTECTED]> wrote: > Ping/ACCEPT > net:proxy.ovh.net,proxy.p19.ovh.net,proxy.rbx.ovh.net,ping.ovh.net $FW ... > would it be possible if the domain name is a dynamic ip? Shorewall tries to resolve the IP once on 'shorewall start', and adds this into iptables. Th

Re: [Shorewall-users] Ping only from known domains

2007-10-12 Thread Prasanna Krishnamoorthy
On 10/12/07, Bart Verstraete <[EMAIL PROTECTED]> wrote: > I don't think the ovh.net domainnames are dynamic? But if I use that > rule I also can ping it from my private dynamic ip? And that I dont > wanne! Then you can ping it from other pc's too. No, if you use the rules you've given you can ping

Re: [Shorewall-users] Ping only from known domains

2007-10-12 Thread Bart Verstraete
Prasanna Krishnamoorthy schreef: > On 10/12/07, Bart Verstraete <[EMAIL PROTECTED]> wrote: > >> Ping/ACCEPT >> net:proxy.ovh.net,proxy.p19.ovh.net,proxy.rbx.ovh.net,ping.ovh.net $FW >> > ... > >> would it be possible if the domain name is a dynamic ip? >> > > Shorewall tries to reso