Yes, I think you are right.
Tom, please remove the bgpd/ospfd lines from that macros before applying.
Maybe I'll post a macro.Quagga for that purpose.
----- Ursprüngliche Mail -----
Von: "Andreas Ferber" <aferber@marcant.net>
An: shorewall-devel@lists.sourceforge.net
Gesendet: Dienstag, 30. Juni 2009 10:26:07 GMT +01:00
Amsterdam/Berlin/Bern/Rom/Stockholm/Wien
Betreff: Re: [Shorewall-devel] Some Macros attached
On Tue, Jun 23, 2009 at 03:08:23PM +0200, Alexander Wilms wrote:
The same thing I wrote about the OSPF macro applies to the BGP macro
as well. tcp/2605 is the management interface, not the BGP protocol,
and should not be included. In 99% of cases you absolutely don't want
to accept management access from your (e)BGP peers.
Andreas
--
Andreas Ferber | MarcanT Internet-Services GmbH
Systemadministration | Ravensberger Str. 10G, D-33602 Bielefeld
aferber@marcant.net | Geschaeftsfuehrer: Thorsten Hojas
USt-ID Nr.: DE 190203238 | Handelsregister: Amtsgericht Bielefeld, HRB 35 827
------------------------------------------------------------------------------
_______________________________________________
Shorewall-devel mailing list
Shorewall-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-devel
------------------------------------------------------------------------------
_______________________________________________
Shorewall-devel mailing list
Shorewall-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-devel