On 03/21/2013 04:55 PM, Matthias Ferdinand wrote:
> as far as I can see, the abstraction of
> 
>   zone => network => group => host
> 
> is strictly hierarchical. I want to setup a rule that allows some basic
> network services for several different client networks, so they all can
> access NTP, mail and proxy servers etc.
> The networks are connected to different interfaces, some of them are
> VLAN interfaces.
> Is it possible to group several networks together and implement this
> using a single "Accept" (+NAT) rule?

No, but it is possible to use the "zone" directly in the rule. In such a
case iptables rules will be created for each network in the zone.


------------------------------------------------------------------------------
Everyone hates slow websites. So do we.
Make your web apps faster with AppDynamics
Download AppDynamics Lite for free today:
http://p.sf.net/sfu/appdyn_d2d_mar
_______________________________________________
Vuurmuur-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/vuurmuur-users

Reply via email to