Hypothetical interfaces file: #ZONE INTERFACE BROADCAST OPTIONS net eth0 detect tcpflags,blacklist,norfc1918,routefilter loc eth1 detect tcpflags loc ppp+ - tcpflags #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE Is the above construct ''officially'' sanctioned? It seems to produce suitable tables.
On Thu, 2003-09-18 at 00:42, Taso Hatzi wrote:> Hypothetical interfaces file: > > #ZONE INTERFACE BROADCAST OPTIONS > net eth0 detect tcpflags,blacklist,norfc1918,routefilter > loc eth1 detect tcpflags > loc ppp+ - tcpflags > #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE > > > Is the above construct ''officially'' sanctioned?Yes. -Tom -- Tom Eastep \ Shorewall - iptables made easy Shoreline, \ http://shorewall.net Washington USA \ teastep@shorewall.net