In that time, I were a baby in shorewall... I just left behind the IPCHAINS
diaper...
Six (6) years later...
From
http://lists.shorewall.net/pipermail/shorewall-users/2002-April/001036.html...
[...]
Imagine having a feature like: "shorewall [troubleshoot] start". In
this
case, all zone combinations will be generated on-the-fly as a POLICY REJECT
INFO.
[...]
>From http://www.shorewall.net/manpages/shorewall.conf.html
[...]
If EXPAND_POLICIES=Yes, then Shorewall-perl will create a separate chain for
each pair of zones covered by the policy. This makes the resulting log
messages easier to interpret since the chain in the messages will have a
name of the form ''a2b'' where ''a'' is the
SOURCE zone and ''b'' is the DEST
zone.
[...]
-Gilson Soares
PS: In fact, since 09-Aug-2007 (4.0.1 release date)
-------------------------------------------------------------------------
This SF.net email is sponsored by the 2008 JavaOne(SM) Conference
Don''t miss this year''s exciting event. There''s still
time to save $100.
Use priority code J8TL2D2.
http://ad.doubleclick.net/clk;198757673;13503038;p?http://java.sun.com/javaone