LinuxSir.cn,穿越时空的Linuxsir!

 找回密码
 注册
搜索
热搜: shell linux mysql
12
返回列表 发新帖
楼主: abcbuzhiming

linuxth以及其它玩防火墙的高手请进,我实在对shorewall没办法了,崩溃中OTZ

[复制链接]
 楼主| 发表于 2007-8-10 10:14:52 | 显示全部楼层
Post by linuxth
嗯,可以如愿的。

嗯,试图让ppp断线重拔,ShareWall应该可以继续工作的(这个需要测试一下)

ps的问题不清楚,没碰到,等你防火墙能正常工作后,再回头看这个问题,是否存在。


如何如愿,请教一个思路……

PS的问题,我今天已经做了一次测试,他这功能很明显是默认的,不是和我配置防火墙有关,你可以看我的截图,在这项目的配置文件里,找不到关闭的方法,我查找了shorewall.conf,查到了这样一段话


  1. FOR ADMINS THAT REPEATEDLY SHOOT THEMSELVES IN THE FOOT
  2. #
  3. # Normally, when a "shorewall stop" command is issued or an error occurs during
  4. # the execution of another shorewall command, Shorewall puts the firewall into
  5. # a state where only traffic to/from the hosts listed in
  6. # /etc/shorewall/routestopped is accepted.
  7. #
  8. # When performing remote administration on a Shorewall firewall, it is
  9. # therefore recommended that the IP address of the computer being used for
  10. # administration be added to the firewall's /etc/shorewall/routestopped file.
  11. #
  12. # Some administrators have a hard time remembering to do this with the result
  13. # that they get to drive across town in the middle of the night to restart
  14. # a remote firewall (or worse, they have to get someone out of bed to drive
  15. # across town to restart a very remote firewall).
  16. #
  17. # For those administrators, we offer ADMINISABSENTMINDED=Yes. With this
  18. # setting, when the firewall enters the 'stopped' state:
  19. #
  20. # All traffic that is part of or related to established connections is still
  21. # allowed and all OUTPUT traffic is allowed. This is in addition to traffic
  22. # to and from hosts listed in /etc/shorewall/routestopped.
  23. #
  24. # If this variable is not set or it is set to the null value then
  25. # ADMINISABSENTMINDED=No is assumed.
  26. #

  27. ADMINISABSENTMINDED=Yes
复制代码


我仔细看了,但是很明显这个参数提供的功能不是关闭该默认功能,而是给你个选择,如果是no,就阻塞所有外部访问,如果是yes,那么在shorewall stop之前已经连接上的访问不会被阻塞,其他后来的访问一律阻塞,我试验也做了证明和我想的一样

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?注册

x
回复 支持 反对

使用道具 举报

发表于 2007-8-10 17:21:19 | 显示全部楼层
/etc/shorewall/routestopped
收到,如你所说,没错。
回复 支持 反对

使用道具 举报

 楼主| 发表于 2007-8-10 18:23:22 | 显示全部楼层
Post by linuxth
/etc/shorewall/routestopped
收到,如你所说,没错。

今天测试后已经得出了结论,pppoe拨号不管是在shorewall前还是在shorewall后启动都能正常拨号,即使中途断线再次播也能拨上,这样就解决大问题了,现在唯一要解决的就是ppp的断线重播问题了……
回复 支持 反对

使用道具 举报

发表于 2007-8-12 20:02:51 | 显示全部楼层
Post by abcbuzhiming
iptables简单?天啊,光看手册我都要疯了,就是因为怕了iptables才跑来用shorewall的

我也用iptables,相当不错。这是我的心得 http://wcw.cublog.cn
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

快速回复 返回顶部 返回列表