Linux Advocate wrote:
> Thanx Tom. The caution has been reworded in the
> website.
> 
>> That's the correct article -- the caution is wrong.
>>
> 
> As further note to this maclist business, can i use
> the params definition of MACS in the rules file as
> shown below;
> 
> SMB/ACCEPT  loc:$MACS  mz
> SMB/ACCEPT  mz         loc

Yes.

> 
> a. Do i have to put a tilde in front of $MACS?

No.

> b. Will the rule above ensure that only the relevant
> hosts from the loc zone( with the allowed mac
> addresses ) can connect to the server in the mz zone
> for SMB ?

Yes.

-Tom
-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ [EMAIL PROTECTED]
PGP Public Key   \ https://lists.shorewall.net/teastep.pgp.key

Attachment: signature.asc
Description: OpenPGP digital signature

-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >>  http://get.splunk.com/
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to