* Tom Eastep wrote:
> On 12/9/10 7:53 PM, Nathan Gibbs wrote:
>> Is this even doable with shorewall?
>>
>> After a packet natches a DROP rule like
>> DROP net:10.0.0.0/8  fw      all
>>
>> if the connection came in on port 80,
>>      redirect it to port 81
>>      let it through
>> else
>>      Drop it like normal
>> endif
> 
> No.

Shoot.
I should have looked at the iptables output and man page before asking.
DROP is DROP and it DROPs, thats why its called DROP.
:-)

> 
> Why don't you just put the REDIRECT rule before the DROP rule?
> 

So I could put that into a macro and call that instead of DROP on my rules.

Am I thinking in the right direction?
Could I get what I want that way?

Thanks.


-- 
Sincerely,

Nathan Gibbs

Systems Administrator
Christ Media
http://www.cmpublishers.com


Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to