shorewall-tcfilters.xml (shorewall-docs-xml-5.2.3.6.tar.bz2) | : | shorewall-tcfilters.xml (shorewall-docs-xml-5.2.6.tar.bz2) | ||
---|---|---|---|---|
skipping to change at line 75 | skipping to change at line 75 | |||
<variablelist> | <variablelist> | |||
<varlistentry> | <varlistentry> | |||
<term><emphasis role="bold">CLASS</emphasis> - | <term><emphasis role="bold">CLASS</emphasis> - | |||
<emphasis>interface</emphasis><emphasis | <emphasis>interface</emphasis><emphasis | |||
role="bold">:</emphasis><emphasis>class</emphasis></term> | role="bold">:</emphasis><emphasis>class</emphasis></term> | |||
<listitem> | <listitem> | |||
<para>The name or number of an <returnvalue>interface</returnvalue> | <para>The name or number of an <returnvalue>interface</returnvalue> | |||
defined in <ulink | defined in <ulink | |||
url="/manpages/shorewall-tcdevices.html">shorewall-tcdevices</ulink>(5 ) | url="shorewall-tcdevices.html">shorewall-tcdevices</ulink>(5) | |||
followed by a <replaceable>class</replaceable> number defined for | followed by a <replaceable>class</replaceable> number defined for | |||
that interface in <ulink | that interface in <ulink | |||
url="/manpages/shorewall-tcclasses.html">shorewall-tcclasses</ulink>(5 ).</para> | url="shorewall-tcclasses.html">shorewall-tcclasses</ulink>(5).</para> | |||
</listitem> | </listitem> | |||
</varlistentry> | </varlistentry> | |||
<varlistentry> | <varlistentry> | |||
<term><emphasis role="bold">SOURCE</emphasis> - {<emphasis | <term><emphasis role="bold">SOURCE</emphasis> - {<emphasis | |||
role="bold">-</emphasis>|<emphasis>address</emphasis>|+<replaceable>ipse t</replaceable>}</term> | role="bold">-</emphasis>|<emphasis>address</emphasis>|+<replaceable>ipse t</replaceable>}</term> | |||
<listitem> | <listitem> | |||
<para>Source of the packet. May be a host or network | <para>Source of the packet. May be a host or network | |||
<replaceable>address</replaceable>. DNS names are not allowed. | <replaceable>address</replaceable>. DNS names are not allowed. | |||
Beginning with Shorewall 4.6.0, an ipset name (prefixed with '+') | Beginning with Shorewall 4.6.0, an ipset name (prefixed with '+') | |||
may be used if your kernel and ip6tables have the <firstterm>Basic | may be used if your kernel and ip6tables have the <firstterm>Basic | |||
Ematch</firstterm> capability and you set BASIC_FILTERS=Yes in | Ematch</firstterm> capability and you set BASIC_FILTERS=Yes in | |||
<ulink url="/manpages/shorewall.conf.html">shorewall.conf | <ulink url="shorewall.conf.html">shorewall.conf | |||
(5)</ulink>. The ipset name may optionally be followed by a number | (5)</ulink>. The ipset name may optionally be followed by a number | |||
or a comma separated list of src and/or dst enclosed in square | or a comma separated list of src and/or dst enclosed in square | |||
brackets ([...]). See <ulink | brackets ([...]). See <ulink | |||
url="/manpages/shorewall-ipsets.html">shorewall-ipsets(5)</ulink> | url="shorewall-ipsets.html">shorewall-ipsets(5)</ulink> | |||
for details.</para> | for details.</para> | |||
</listitem> | </listitem> | |||
</varlistentry> | </varlistentry> | |||
<varlistentry> | <varlistentry> | |||
<term><emphasis role="bold">DEST</emphasis> - {<emphasis | <term><emphasis role="bold">DEST</emphasis> - {<emphasis | |||
role="bold">-</emphasis>|<emphasis>address</emphasis>|+<replaceable>ipse t</replaceable>}</term> | role="bold">-</emphasis>|<emphasis>address</emphasis>|+<replaceable>ipse t</replaceable>}</term> | |||
<listitem> | <listitem> | |||
<para>Destination of the packet. May be a host or network | <para>Destination of the packet. May be a host or network | |||
<replaceable>address</replaceable>. DNS names are not allowed. | <replaceable>address</replaceable>. DNS names are not allowed. | |||
Beginning with Shorewall 4.6.0, an ipset name (prefixed with '+') | Beginning with Shorewall 4.6.0, an ipset name (prefixed with '+') | |||
may be used if your kernel and ip6tables have the <firstterm>Basic | may be used if your kernel and ip6tables have the <firstterm>Basic | |||
Ematch</firstterm> capability and you set BASIC_FILTERS=Yes in | Ematch</firstterm> capability and you set BASIC_FILTERS=Yes in | |||
<ulink url="/manpages/shorewall.conf.html">shorewall.conf | <ulink url="shorewall.conf.html">shorewall.conf | |||
(5)</ulink>. The ipset name may optionally be followed by a number | (5)</ulink>. The ipset name may optionally be followed by a number | |||
or a comma separated list of src and/or dst enclosed in square | or a comma separated list of src and/or dst enclosed in square | |||
brackets ([...]). See <ulink | brackets ([...]). See <ulink | |||
url="/manpages/shorewall-ipsets.html">shorewall-ipsets(5)</ulink> | url="shorewall-ipsets.html">shorewall-ipsets(5)</ulink> | |||
for details.</para> | for details.</para> | |||
<para>You may exclude certain hosts from the set already defined | <para>You may exclude certain hosts from the set already defined | |||
through use of an <emphasis>exclusion</emphasis> (see <ulink | through use of an <emphasis>exclusion</emphasis> (see <ulink | |||
url="/manpages/shorewall-exclusion.html">shorewall-exclusion</ulink>(5 )).</para> | url="shorewall-exclusion.html">shorewall-exclusion</ulink>(5)).</para> | |||
</listitem> | </listitem> | |||
</varlistentry> | </varlistentry> | |||
<varlistentry> | <varlistentry> | |||
<term><emphasis role="bold">PROTO</emphasis> - {<emphasis | <term><emphasis role="bold">PROTO</emphasis> - {<emphasis | |||
role="bold">-</emphasis>|{<emphasis>protocol-number</emphasis>|<emphasis >protocol-name</emphasis>|<emphasis | role="bold">-</emphasis>|{<emphasis>protocol-number</emphasis>|<emphasis >protocol-name</emphasis>|<emphasis | |||
role="bold">all}[,...]}</emphasis></term> | role="bold">all}[,...]}</emphasis></term> | |||
<listitem> | <listitem> | |||
<para>Protocol.</para> | <para>Protocol.</para> | |||
skipping to change at line 358 | skipping to change at line 358 | |||
<para>/etc/shorewall/tcfilters</para> | <para>/etc/shorewall/tcfilters</para> | |||
<para>/etc/shorewall6/tcfilters</para> | <para>/etc/shorewall6/tcfilters</para> | |||
</refsect1> | </refsect1> | |||
<refsect1> | <refsect1> | |||
<title>See ALSO</title> | <title>See ALSO</title> | |||
<para><ulink | <para><ulink | |||
url="/traffic_shaping.htm">http://www.shorewall.net/traffic_shaping.htm</uli nk></para> | url="../traffic_shaping.htm">https://shorewall.org/traffic_shaping.htm</ulin k></para> | |||
<para><ulink | <para><ulink | |||
url="/MultiISP.html">http://www.shorewall.net/MultiISP.html</ulink></para> | url="../MultiISP.html">https://shorewall.org/MultiISP.html</ulink></para> | |||
<para><ulink | <para><ulink | |||
url="/PacketMarking.html">http://www.shorewall.net/PacketMarking.html</ulink ></para> | url="../PacketMarking.html">https://shorewall.org/PacketMarking.html</ulink> </para> | |||
<para><ulink | <para><ulink | |||
url="/configuration_file_basics.htm#Pairs">http://www.shorewall.net/configur ation_file_basics.htm#Pairs</ulink></para> | url="../configuration_file_basics.htm#Pairs">https://shorewall.org/configura tion_file_basics.htm#Pairs</ulink></para> | |||
<para>shorewall(8)</para> | <para>shorewall(8)</para> | |||
</refsect1> | </refsect1> | |||
</refentry> | </refentry> | |||
End of changes. 11 change blocks. | ||||
11 lines changed or deleted | 11 lines changed or added |