On 05/26/2013 07:01 PM, Dash Four wrote:
> 
> Tom Eastep wrote:
>> On 05/26/2013 06:12 PM, Dash Four wrote:
>>   
>>> Tom Eastep wrote:
>>>     
>>>> 2)  A new 'local' zone TYPE has been added to /etc/shorewall[6]/zones.
>>>>     A 'local' zone is similar to an 'ipv4' ('ipv6') zone, except that
>>>>     rules and policies to/from a 'local' zone may only be to/from the
>>>>     firewall zone, vserver zones or other 'local' zones.
>>>>   
>>>>       
>>> What happens if I need these "local" zones to be completely isolated? In 
>>> other words, if I define "local1" and "local2" and wish to completely 
>>> isolate the traffic on these 2 local zones (in other words, ask 
>>> shorewall to manage traffic only in fw2local1, local12fw, fw2local2 and 
>>> local22fw, but *not* local12local2 or local22local1), what then?
>>>
>>>     
>>
>> Define those policies as NONE.
>>   
> Right, so every time I add a local zone, then I have to manually update 
> the policy file and insert NONE for every conceivable combination 
> between all my other local zones? As if I am going to do that...

Give me a break; I have arthritic hands and I type all day long.

So buck up and use your fingers, Mr-4; because when it comes to
Shorewall, my keystrokes are much more valuable than yours.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Try New Relic Now & We'll Send You this Cool Shirt
New Relic is the only SaaS-based application performance monitoring service 
that delivers powerful full stack analytics. Optimize and monitor your
browser, app, & servers with just a few lines of code. Try New Relic
and get this awesome Nerd Life shirt! http://p.sf.net/sfu/newrelic_d2d_may
_______________________________________________
Shorewall-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-devel

Reply via email to