Shorewall 5.0 Documentation

Tom Eastep

Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation; with no Invariant Sections, with no Front-Cover, and with no Back-Cover Texts. A copy of the license is included in the section entitled GNU Free Documentation License.

2023/02/18


Table of Contents

Frequently Used Articles
Documentation for Earlier Versions
Index to the HOWTOs and Other Articles

Frequently Used Articles

Documentation for Earlier Versions

Shorewall 4.4/4.6 Documentation

Shorewall 4.0/4.2 Documentation

Index to the HOWTOs and Other Articles

6to4 and 6in4 TunnelsKVM (Kernel-mode Virtual Machine)Shorewall on a Laptop
AccountingLinux Containers (LXC)Shorewall Perl
ActionsLinux-vserverShorewall Setup Guide
Aliased (virtual) Interfaces (e.g., eth0:0)Limiting Connection RatesSMB
Anatomy of ShorewallLoggingSNAT (Source Network Address Translation)
Anti-Spoofing MeasuresMacrosSplit DNS the Easy Way
AUDIT Target supportMAC VerificationSquid with Shorewall
Bandwidth ControlManpagesStarting/stopping the Firewall
Blacklisting/WhitelistingManual ChainsStatic (one-to-one) NAT
Bridge: Bridge/FirewallMasqueradingSupport
Bridge: No firewalling of traffic between bridge portMultiple Internet Connections from a Single FirewallTips and Hints
Building Shorewall from GITMultiple Zones Through One InterfaceTraffic Shaping/QOS - Simple
Compiled Programs My Shorewall ConfigurationTraffic Shaping/QOS - Complex
Commands Netfilter OverviewTransparent Proxy
Configuration File BasicsNetwork MappingUPnP
DHCPOne-to-one NAT (Static NAT)OpenVZ
DNAT (Destination Network Address Translation)OpenVPNUpgrade Issues
DockerOperating ShorewallUpgrading to Shorewall 4.4 (Upgrading Debian Lenny to Squeeze)
Dynamic ZonesPacket MarkingVPN
ECN Disabling by host or subnetPacket Processing in a Shorewall-based FirewallVPN Passthrough
Events'Ping' ManagementWhite List Creation
Extension Scripts (User Exits)Port ForwardingXen - Shorewall in a Bridged Xen DomU
Fallback/UninstallPort InformationXen - Shorewall in Routed Xen Dom0
FAQsPort Knocking (deprecated) 
FeaturesPort Knocking, Auto Blacklisting and Other Uses of the 'Recent Match' 
Forwarding Traffic on the Same InterfacePPTP 
FTP and ShorewallProxy ARP 
Fool's FirewallQuickStart Guides 
Helpers/Helper ModulesRelease Model 
Installation/UpgradeRequirements 
IPP2PRouting and Shorewall 
IPSECRouting on One Interface 
IpsetsSamba 
IPv6 SupportShared Shorewall/Shorewall6 Configuration 
ISO 3661 Country CodesShorewall Events 
Kazaa FilteringShorewall Init 
Kernel ConfigurationShorewall Lite