⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 shorewall-routestopped.5

📁 sharewall is very good
💻 5
字号:
.\"     Title: shorewall-routestopped.\"    Author: [FIXME: author] [see http://docbook.sf.net/el/author].\" Generator: DocBook XSL Stylesheets v1.74.0 <http://docbook.sf.net/>.\"      Date: 03/19/2009.\"    Manual: [FIXME: manual].\"    Source: [FIXME: source].\"  Language: English.\".TH "SHOREWALL\-ROUTESTOP" "5" "03/19/2009" "[FIXME: source]" "[FIXME: manual]".\" -----------------------------------------------------------------.\" * (re)Define some macros.\" -----------------------------------------------------------------.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.\" toupper - uppercase a string (locale-aware).\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.de toupper.tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ\\$*.tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz...\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.\" SH-xref - format a cross-reference to an SH section.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.de SH-xref.ie n \{\.\}.toupper \\$*.el \{\\\$*.\}...\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.\" SH - level-one heading that works better for non-TTY output.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.de1 SH.\" put an extra blank line of space above the head in non-TTY output.if t \{\.sp 1.\}.sp \\n[PD]u.nr an-level 1.set-an-margin.nr an-prevailing-indent \\n[IN].fi.in \\n[an-margin]u.ti 0.HTML-TAG ".NH \\n[an-level]".it 1 an-trap.nr an-no-space-flag 1.nr an-break-flag 1\." make the size of the head bigger.ps +3.ft B.ne (2v + 1u).ie n \{\.\" if n (TTY output), use uppercase.toupper \\$*.\}.el \{\.nr an-break-flag 0.\" if not n (not TTY), use normal case (not uppercase)\\$1.in \\n[an-margin]u.ti 0.\" if not n (not TTY), put a border/line under subheading.sp -.6\l'\n(.lu'.\}...\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.\" SS - level-two heading that works better for non-TTY output.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.de1 SS.sp \\n[PD]u.nr an-level 1.set-an-margin.nr an-prevailing-indent \\n[IN].fi.in \\n[IN]u.ti \\n[SN]u.it 1 an-trap.nr an-no-space-flag 1.nr an-break-flag 1.ps \\n[PS-SS]u\." make the size of the head bigger.ps +2.ft B.ne (2v + 1u).if \\n[.$] \&\\$*...\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.\" BB/BE - put background/screen (filled box) around block of text.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.de BB.if t \{\.sp -.5.br.in +2n.ll -2n.gcolor red.di BX.\}...de EB.if t \{\.if "\\$2"adjust-for-leading-newline" \{\.sp -1.\}.br.di.in.ll.gcolor.nr BW \\n(.lu-\\n(.i.nr BH \\n(dn+.5v.ne \\n(BHu+.5v.ie "\\$2"adjust-for-leading-newline" \{\\M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[].\}.el \{\\M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[].\}.in 0.sp -.5v.nf.BX.in.sp .5v.fi.\}...\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.\" BM/EM - put colored marker in margin next to block of text.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.de BM.if t \{\.br.ll -2n.gcolor red.di BX.\}...de EM.if t \{\.br.di.ll.gcolor.nr BH \\n(dn.ne \\n(BHu\M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[].in 0.nf.BX.in.fi.\}...\" -----------------------------------------------------------------.\" * set default formatting.\" -----------------------------------------------------------------.\" disable hyphenation.nh.\" disable justification (adjust text to left margin only).ad l.\" -----------------------------------------------------------------.\" * MAIN CONTENT STARTS HERE *.\" -----------------------------------------------------------------.SH "Name"routestopped \- The Shorewall file that governs what traffic flows through the firewall while it is in \'stopped\' state\&..SH "Synopsis".fam C.HP \w'\fB/etc/shorewall/routestopped\fR\ 'u\fB/etc/shorewall/routestopped\fR.fam.SH "Description".PPThis file is used to define the hosts that are accessible when the firewall is stopped or is being stopped\&. When shorewall\-shell is being used, the file also determines those hosts that are accessible when the firewall is in the process of being [re]started\&..PPThe columns in the file are as follows\&..PP\fBINTERFACE\fR \- \fIinterface\fR.RS 4Interface through which host(s) communicate with the firewall.RE.PP\fBHOST(S)\fR (Optional) \- [\fB\-\fR|\fIaddress\fR[,\fIaddress\fR]\&.\&.\&.].RS 4Comma\-separated list of IP/subnet addresses\&. If your kernel and iptables include iprange match support, IP address ranges are also allowed\&..spIf left empty or supplied as "\-", 0\&.0\&.0\&.0/0 is assumed\&..RE.PP\fBOPTIONS\fR (Optional) \- [\fB\-\fR|\fIoption\fR[\fB,\fR\fIoption\fR]\&.\&.\&.].RS 4A comma\-separated list of options\&. The order of the options is not important but the list can contain no embedded whitespace\&. The currently\-supported options are:.PP\fBrouteback\fR.RS 4Set up a rule to ACCEPT traffic from these hosts back to themselves\&..RE.PP\fBsource\fR.RS 4Allow traffic from these hosts to ANY destination\&. Without this option or the\fBdest\fRoption, only traffic from this host to other listed hosts (and the firewall) is allowed\&. If\fBsource\fRis specified then\fBrouteback\fRis redundant\&..RE.PP\fBdest\fR.RS 4Allow traffic to these hosts from ANY source\&. Without this option or the\fBsource\fRoption, only traffic from this host to other listed hosts (and the firewall) is allowed\&. If\fBdest\fRis specified then\fBrouteback\fRis redundant\&..RE.PP\fBcritical\fR.RS 4Allow traffic between the firewall and these hosts throughout \'[re]start\', \'stop\' and \'clear\'\&. Specifying\fBcritical\fRon one or more entries will cause your firewall to be "totally open" for a brief window during each of those operations\&. Examples of where you might want to use this are:.sp.RS 4.ie n \{\\h'-04'\(bu\h'+03'\c.\}.el \{\.sp -1.IP \(bu 2.3.\}\'Ping\' nodes with heartbeat\&..RE.sp.RS 4.ie n \{\\h'-04'\(bu\h'+03'\c.\}.el \{\.sp -1.IP \(bu 2.3.\}LDAP server(s) if you use LDAP Authentication.RE.sp.RS 4.ie n \{\\h'-04'\(bu\h'+03'\c.\}.el \{\.sp -1.IP \(bu 2.3.\}NFS Server if you have an NFS\-mounted root filesystem\&..RE.RE.PPnotrack.RS 4The traffic will be exempted from conntection tracking\&..RE.RE.PPPROTO (Optional) \(en \fIprotocol\-name\-or\-number\fR.RS 4Only available with Shorewall\-perl 4\&.2\&.7 and later\&..RE.PPDEST PORT(S) (Optional) \(en \fIservice\-name/port\-number\-list\fR.RS 4Only available with Shorewall\-perl 4\&.2\&.7 and later\&. A comma\-separated list of port numbers and/or service names from\FC/etc/services\F[]\&. May also include port ranges of the form\fIlow\-port\fR:\fIhigh\-port\fRif your kernel and iptables include port range support\&..RE.PPSOURCE PORT(S) (Optional) \(en \fIservice\-name/port\-number\-list\fR.RS 4Only available with Shorewall\-perl 4\&.2\&.7 and later\&. A comma\-separated list of port numbers and/or service names from\FC/etc/services\F[]\&. May also include port ranges of the form\fIlow\-port\fR:\fIhigh\-port\fRif your kernel and iptables include port range support\&..RE.if n \{\.sp.\}.RS 4.BM yellow.it 1 an-trap.nr an-no-space-flag 1.nr an-break-flag 1.br.ps +1\fBNote\fR.ps -1.br.PPThe\fBsource\fRand\fBdest\fRoptions work best when used in conjunction with ADMINISABSENTMINDED=Yes in\m[blue]\fBshorewall\&.conf\fR\m[]\&\s-2\u[1]\d\s+2(5)\&..sp .5v.EM yellow.RE.SH "Example".PPExample 1:.RS 4.sp.if n \{\.RS 4.\}.fam C.ps -1.nf.BB lightgray        #INTERFACE      HOST(S)                 OPTIONS         PROTO          DEST       SOURCE        #                                                                      PORT(S)    PORT(S)        eth2            192\&.168\&.1\&.0/24        eth0            192\&.0\&.2\&.44        br0             \-                       routeback        eth3            \-                       source        eth4            \-                       notrack        41.EB lightgray.fi.fam.ps +1.if n \{\.RE.\}.RE.SH "FILES".PP/etc/shorewall/routestopped.SH "See ALSO".PP\m[blue]\fBhttp://shorewall\&.net/starting_and_stopping_shorewall\&.htm\fR\m[].PPshorewall(8), shorewall\-accounting(5), shorewall\-actions(5), shorewall\-blacklist(5), shorewall\-hosts(5), shorewall\-interfaces(5), shorewall\-ipsec(5), shorewall\-maclist(5), shorewall\-masq(5), shorewall\-nat(5), shorewall\-netmap(5), shorewall\-params(5), shorewall\-policy(5), shorewall\-providers(5), shorewall\-proxyarp(5), shorewall\-route_rules(5), shorewall\-rules(5), shorewall\&.conf(5), shorewall\-tcclasses(5), shorewall\-tcdevices(5), shorewall\-tcrules(5), shorewall\-tos(5), shorewall\-tunnels(5), shorewall\-zones(5).SH "Notes".IP " 1." 4shorewall.conf.RS 4\%http://www.shorewall.net/manpages/shorewall.conf.html.RE

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -