[Shorewall-users] Compicated config?

Tom Eastep teastep@shorewall.net
Mon, 28 Jan 2002 07:42:22 -0800

Hello Wolfgang,

On Monday 28 January 2002 07:15 am, Lumpp, Wolfgang wrote:
> Hello,
> at the moment, I'm trying to set up the following config:
> several subnets from and which are offices.
> Most of them are connected through the internal interface eth0.
> But some are connected by VPN, made by a cisco, which is also our gatew=
> to the ISP.
> (eth1 of firewall)
> Now I thought about of zones in the form:
> offa=09officeA
> offb=09officeB
> and so on.
> Some of these zones connected to the internal (eth0), some to the VPN
> (eth1).
> I want to split the zones, because I want to have the traffic from/to t=
> offices.
> Whats the best way? I've read something about to set the interfaces to
> multi.
> And this could drive me into the wrong road ;-)
> Any help is highly appreciated

For those interfaces that are associated with multiple zones, don't speci=
fy a=20
zone in /etc/shorewall/interfaces:


You can then define the zones in the /etc/shorewall/hosts file:


Tom Eastep    \ A Firewall for Linux 2.4.*
AIM: tmeastep  \ http://www.shorewall.net
ICQ: #60745924  \ teastep@shorewall.net