> Nevermind. The problem is that use invoked the Invalid action
from
> within the INVALID section. If you replace 'Invalid(DROP)' with 'DROP'
> in that section, it works correctly.
Make that ...that *you* invoked the...".
OK thank you for your time. Sorry for that mistake.
However I notice there is still an extra comment in the fw-net and net-fw
chains :
Chain fw-net (1 references)
pkts bytes target prot opt in out source
destination
12 624 _fw-net all -- * * 0.0.0.0/0
0.0.0.0/0 ctstate INVALID /* Drop invalid packets generated by
weather applet */
Thus this comment is specified twice per direction : first in the fw-net and
then in _fw-net (right place).
------------------------------------------------------------------------------
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users