On Thu, 7 Jul 2011, Dominic Benson wrote:

> Date: Wed, 6 Jul 2011 16:35:51
> From: Dominic Benson <[email protected]>
> Reply-To: Shorewall Users <[email protected]>
> To: Shorewall Users <[email protected]>
> Subject: [Shorewall-users] Tproxy with Shorewall6
> 
> Hi Tom,
>
> A while ago I was trying to get tproxy working with shorewall6 - at the time 
> I had to put it on the back burner owing to the iptables version dependency.
>
> I have since put in a new router, with recent kernel and iptables, so I have 
> now got it working for real, and it works well - thanks.
>
> One niggle I did encounter was in specifying address as the third argument to 
> TPROXY in tcrules6 - the colons in ipv6 addresses seem to cause problems. I 
> avoided the problem by specifying it as localhost rather than ::1. I don't 
> know if there's a way of writing the address that is supported.
>
> Thanks for the great work!
>
> Dominic

I don't know about TPROXY in particular, but in most places in shorewall6, 
you can enclose the IPv6 addresses (including prefix length) in angle 
brackets, like so (all mine are in hosts so far, so these are with 
interfaces):
eth0:<2001:470:1::/64,fe80::/10>

Note that multiple entries are enclosed in one set of brackets, rather 
than one pair of brackets per address range.


-- 
J. Randall Owens | http://www.ghiapet.net/
ProofReading Markup Language | http://prml.sourceforge.net/



------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security 
threats, fraudulent activity, and more. Splunk takes this data and makes 
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2d-c2
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to