On 4/25/2015 3:22 PM, Guilsson . wrote: > Reading the docs I didn't realize I need to setup things outside Shorewall. > Don't you mind make this information more explicit at documentation ? >
What would be the point of having Shorewall ipset support if you had to define their contents in Shorewall configuration files? The reason for using ipsets is because their contents can be dynamically altered without having to restart Shorewall. If you only use ipsets in Shorewall (and not in Shorewall6), then: - Create your ipsets - Load them using the ipset utility - Add your shorewall rules that use the ipsets - Set SAVE_IPSETS in shorewall.conf - Restart Shorewall - Execute the 'savesets' command (if you are running 4.6.8). If not, it is a good idea to 'shorewall stop && shorewall start'. -Tom -- Tom Tom Eastep http://www.shorewall.net
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------ One dashboard for servers and applications across Physical-Virtual-Cloud Widest out-of-the-box monitoring support with 50+ applications Performance metrics, stats and reports that give you Actionable Insights Deep dive visibility with transaction tracing using APM Insight. http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
