routestopped
The Shorewall file that governs what traffic flows through the firewall while it is in the 'stopped' state.
- Provided by: shorewall (Version: 4.5.21.6-1)
- Report a bug
The Shorewall file that governs what traffic flows through the firewall while it is in the 'stopped' state.
/etc/shorewall/routestopped
This file is deprecated in favor of the shorewall-stoppedrules[1](5) file.
This file is used to define the hosts that are accessible when the firewall is stopped or is being stopped.
Changes to this file do not take effect until after the next shorewall start or shorewall restart command.
The columns in the file are as follows (where the column name is followed by a different name in parentheses, the different name is used in the alternate specification syntax).
INTERFACE - interface
HOST(S) (hosts) - [-|address[,address]...]
If left empty or supplied as "-", 0.0.0.0/0 is assumed.
OPTIONS - [-|option[,option]...]
routeback
source
dest
notrack
PROTO (Optional) – protocol-name-or-number
DEST PORT(S) (dport) – service-name/port-number-list
SOURCE PORT(S) (sport) – service-name/port-number-list
Beginning with Shorewall 4.5.15, you may place '=' in this column, provided that the DEST PORT(S) column is non-empty. This causes the rule to match when either the source port or the destination port in a packet matches one of the ports specified in DEST PORTS(S). Use of '=' requires multi-port match in your iptables and kernel.
The source and dest options work best when used in conjunction with ADMINISABSENTMINDED=Yes in shorewall.conf[3](5).
Example 1:
#INTERFACE HOST(S) OPTIONS PROTO DEST SOURCE
# PORT(S) PORT(S)
eth2 192.168.1.0/24
eth0 192.0.2.44
br0 - routeback
eth3 - source
eth4 - notrack 41
/etc/shorewall/routestopped
http://shorewall.net/starting_and_stopping_shorewall.htm
http://shorewall.net/configuration_file_basics.htm#Pairs
shorewall(8), shorewall-accounting(5), shorewall-actions(5), shorewall-blacklist(5), shorewall-hosts(5), shorewall_interfaces(5), shorewall-ipsets(5), shorewall-maclist(5), shorewall-masq(5), shorewall-nat(5), shorewall-netmap(5), shorewall-params(5), shorewall-policy(5), shorewall-providers(5), shorewall-proxyarp(5), shorewall-rtrules(5), shorewall-rules(5), shorewall.conf(5), shorewall-secmarks(5), shorewall-tcclasses(5), shorewall-tcdevices(5), shorewall-tcrules(5), shorewall-tos(5), shorewall-tunnels(5), shorewall-zones(5)