On 6/7/11 6:53 AM, Mr Dash Four wrote:
> 
>> Thank you for using Shorewall,
>> -The Shorewall Team
>>   
> A couple of queries:
> 
> 1. In .20 there is a new option in compiler.pl called "--confess". What 
> is the purpose of it? I already know what FAKE_AUDIT does.

--confess is what gets set when the new -T option is specified in
'check', 'compile', etc.

> 2. In both Drop and Reject default actions there is Auth(REJECT). 
> Shouldn't that be Auth(DROP) in the Drop action instead?

Dropping AUTH can cause connection issues with (antiquated) servers that
still use it. So the default is to REJECT it; see Shorewall FAQ 4.

> 3. Is AUTOMAKE=Yes reliable if my files are in a non-standard shorewall 
> directory (i.e. not in /etc/shorewall), but still in shorewall's path?

Not currently.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
EditLive Enterprise is the world's most technically advanced content
authoring tool. Experience the power of Track Changes, Inline Image
Editing and ensure content is compliant with Accessibility Checking.
http://p.sf.net/sfu/ephox-dev2dev
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to