Linux and UNIX Man Pages

Linux & Unix Commands - Search Man Pages

shorewall-init(8) [debian man page]

SHOREWALL-INIT(8)						  [FIXME: manual]						 SHOREWALL-INIT(8)

NAME
shorewall-init - Companion package SYNOPSIS
/etc/init.d/shorewall-init [start|stop] DESCRIPTION
Shorewall-init is an optional package (added in Shorewall 4.4.10) that can be installed along with Shorewall, Shorewall6, Shorewall-lite and/or Shorewall6-lite. It provides two key features: 1. It can close (stop) the firewall during boot prior to starting the network. This can prevent unwanted connections from being accepted after the network comes up but before the firewall is started. 2. It can interface with your distribution's ifup/ifdown scripts and/or NetworkManager to allow firewall actions when an interface starts or stops. These two capabilities can be enabled separately. After you install the shorewall-init package, you can activate it by modifying the Shorewall-init configuration file: o On Debian-based system, the file is /etc/default/shorewall-init. o On other systems, the file is /etc/sysconfig/shorewall-init. To activate the safe boot feature, edit the configuration file and set PRODUCTS to a space-separated list of Shorewall products that you want to be closed before networking starts. Example: PRODUCTS="shorewall shorewall6" You also must insure that the compiled scripts for the listed products are compiled using Shorewall 4.4.10 or later. Shorewall shorewall compile Shorewall6 shorewall6 compile Shorewall-lite On the administrative system, enter the command shorewall export firewall from the firewall's configuration directory. Shorewall6-lite On the administrative system, enter the command shorewall6 export firewall from the firewall's configuration directory. The second feature (ifup/ifdown and NetworkManager integration) should only be activated on systems that do not use a link status monitor line swping or LSM. o Edit the configuration file and set IFUPDOWN=1 For NetworkManager integration, you will want to disable firewall startup at boot and delay it to when your interface comes up. For this to work correctly, you must set the required or the optional option on at least one interface then: o On Debian-based systems, edit /etc/default/product for each product listed in the PRODUCTS setting and set startup=0. o On other systems, use the distribution's service control tool (insserv, chkconfig, etc.) to disable startup of the products listed in the PRODUCTS setting. On a laptop with both ethernet and wireless interfaces, you will want to make both interfaces optional and set the REQUIRE_INTERFACE option to Yes in shorewall.conf[1](5) or shorewall6.conf[2] (5). This causes the firewall to remain stopped until at least one of the interfaces comes up. FILES
/etc/default/shorewall-init (Debian-based systems) or /etc/sysconfig/shorewall-init (other distributions) SEE ALSO
shorewall(8), shorewall-accounting(5), shorewall-actions(5), shorewall-blacklist(5), shorewall-hosts(5), shorewall_interfaces(5), shorewall-ipsets(5), shorewall-maclist(5), shorewall-masq(5), shorewall-nat(5), shorewall-netmap(5), shorewall-params(5), shorewall-policy(5), shorewall-providers(5), shorewall-proxyarp(5), shorewall-rtrules(5), shorewall-routestopped(5), shorewall-rules(5), shorewall.conf(5), shorewall-secmarks(5), shorewall-tcclasses(5), shorewall-tcdevices(5), shorewall-tcrules(5), shorewall-tos(5), shorewall-tunnels(5), shorewall-zones(5) NOTES
1. shorewall.conf http://www.shorewall.net/manpages/shorewall.conf.html 2. shorewall6.conf http://www.shorewall.net/manpages/../Manpages6/shorewall6.conf.html [FIXME: source] 06/28/2012 SHOREWALL-INIT(8)

Check Out this Related Man Page

SHOREWALL-MODULES(5)						  [FIXME: manual]					      SHOREWALL-MODULES(5)

NAME
modules - Shorewall file SYNOPSIS
/usr/share/shorewall/modules /usr/share/shorewall/helpers DESCRIPTION
These files specify which kernel modules Shorewall will load before trying to determine your iptables/kernel's capabilities. The modules file is used when LOAD_HELPERS_ONLY=No in shorewall.conf[1](8); the helpers file is used when LOAD_HELPERS_ONLY=Yes Each record in the files has the following format: loadmodule modulename [moduleoption...] The modulename names a kernel module (without suffix). Shorewall will search for modules based on your MODULESDIR and MODULE_SUFFIX settings in shorewall.conf[1](8). The moduleoptions are passed to modprobe (if installed) or to insmod. The /usr/share/shorewall/modules file contains a large number of modules. Users are encouraged to copy the file to /etc/shorewall/modules and modify the copy to load only the modules required or to use LOAD_HELPERS_ONLY=Yes..if n .sp Note If you build monolithic kernels and have not installed module-init-tools, then create an empty /etc/shorewall/modules file; that will prevent Shorewall from trying to load modules at all. EXAMPLE
loadmodule ip_conntrack_ftp ports=21,221 FILES
/usr/share/shorewall/modules /usr/share/shorewall/helpers /etc/shorewall/modules /etc/shorewall/helpers SEE ALSO
shorewall(8), shorewall-accounting(5), shorewall-actions(5), shorewall-blacklist(5), shorewall-hosts(5), shorewall_interfaces(5), shorewall-ipsets(5), shorewall-maclist(5), shorewall-masq(5), shorewall-nat(5), shorewall-netmap(5), shorewall-params(5), shorewall-policy(5), shorewall-providers(5), shorewall-proxyarp(5), shorewall-rtrules(5), shorewall-routestopped(5), shorewall-rules(5), shorewall.conf(5), shorewall-secmarks(5), shorewall-tcclasses(5), shorewall-tcdevices(5), shorewall-tcrules(5), shorewall-tos(5), shorewall-tunnels(5), shorewall-zones(5) NOTES
1. shorewall.conf http://www.shorewall.net/manpages/shorewall.conf.html [FIXME: source] 06/28/2012 SHOREWALL-MODULES(5)
Man Page