[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [suse-security] SuSEfirewall2 and multiple IPs for interface



Hello Ralf,

you should have a look at  Shorewall instead of SuSEfirewall2 !
Download:    germany.shorewall.net

I personally find it much easier to manage and even more powerful
than SuSE's scripts, I'm sorry !
I abandoned SuSEfirewall2 and since I use shorewall-scripts I am
able to manage almost everything like vpn (ipsec or openvpn, you
could even define your own ...), building dmz's with more complex
setups like 4 interfaces or such things .... I really like this tool !

Greetings, Philipp


Ralf Ronneburger schrieb:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi André,
hi list,

André Sänger wrote:
| I have the following working setup on SuSE 9.0:
|
| FW_DEV_EXT="eth1 eth1:1"
| FW_SERVICES_EXT_TCP="80 443"

thank you, that works perfect for me!

I've set my network up as above, now outgoing traffic is always
masqueraded to the IP of eth1 in the above example. Is there a way to
avoid this and tell SuSEfirewall2 where to masquerade it to?

Greetings,

Ralf
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFANPFXLbWu9MVtJiYRAsHxAKCc3hOrd/Ae6ZffnICTCd6Ls19RxwCdEu5q
Ak4TrS5yqLq5Z2KuTWIXwbo=
=Da5W
-----END PGP SIGNATURE-----




--
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-help@xxxxxxxx
Security-related bug reports go to security@xxxxxxx, not here