From: Marc S. <m.s...@po...> - 2005-04-19 15:13:07
|
Ok that sounds logical ;-). I'll change: /etc/shorewall/masq: #INTERFACE SUBNET ADDRESS eth1 eth0 213.155.200.43 #LAST LINE -- ADD YOUR ENTRIES ABOVE THIS LINE -- DO NOT REMOVE To: /etc/shorewall/masq: #INTERFACE SUBNET ADDRESS eth1 ppp0 213.155.200.43 #LAST LINE -- ADD YOUR ENTRIES ABOVE THIS LINE -- DO NOT REMOVE In about 2 hours (when I'm back home) thanks -----Original Message----- From: sho...@li... [mailto:sho...@li...] On Behalf Of Tom = Eastep Sent: marted=EC 19 aprile 2005 17.00 To: Mailing List for Shorewall Users Subject: Re: [Shorewall-users] allow ssh access from net to fw? Marc Schillinger wrote: > Why? The example in the masq file says: >=20 > # Example 1: > # > # You have a simple masquerading setup where eth0 > connects to > # a DSL or cable modem and eth1 connects to your local > network > # with subnet 192.168.0.0/24. > # > # Your entry in the file can be either: > # > # #INTERFACE SUBNET ADDRESS > # eth0 eth1 > # > # or > # > # #INTERFACE SUBNET ADDRESS > # eth0 192.168.0.0/24=20 >=20 > Whith the difference that my interfaces are inverted: (eth1 ->adsl and = > eth0 > ->lan). > Am I missunderstanding the example? >=20 The interface named in the #INTERFACE column should be the same as your 'net' interface in /etc/shorewall/interfaces: /etc/shorewall/interfaces: #ZONE INTERFACE BROADCAST OPTIONS net ppp0 - dhcp,norfc1918,tcpflags loc eth0 detect tcpflags #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE /etc/shorewall/masq: #INTERFACE SUBNET ADDRESS eth1 eth0 213.155.200.43 #LAST LINE -- ADD YOUR ENTRIES ABOVE THIS LINE -- DO NOT REMOVE One of the two files must be wrong... -Tom --=20 Tom Eastep \ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ te...@sh... PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key _______________________________________________ Shorewall-users mailing list Post: Sho...@li... Subscribe/Unsubscribe: https://lists.shorewall.net/mailman/listinfo/shorewall-users Support: http://www.shorewall.net/support.htm FAQ: http://www.shorewall.net/FAQ.htm |