Karsten Bräckelmann wrote:

> ===================================================================
> --- Shorewall-common/macro.IPP        (revision 5936)
> +++ Shorewall-common/macro.IPP        (working copy)
> @@ -9,4 +9,5 @@
>  #ACTION      SOURCE  DEST    PROTO   DEST    SOURCE  ORIGINAL        RATE    
> USER/
>  #                            PORT    PORT(S) DEST            LIMIT   GROUP
>  PARAM        -       -       tcp     631
> +PARAM        -       -       udp     631
>  #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE

Karsten,

Have you tested this? I though that IPP used UDP 631 broadcasts; if so,
you need to also include the (very insecure) rule:

        PARAM   DEST    SOURCE  udp     -       631

That allows any UDP traffic with source port 631 in the reverse direction.

-Tom
-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ [EMAIL PROTECTED]
PGP Public Key   \ https://lists.shorewall.net/teastep.pgp.key

-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
Shorewall-devel mailing list
Shorewall-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-devel

Reply via email to