Have you tried Firewall Builder? You can use Firewall Builder to make all the rules for iptables.<br><br><br><br><div class="gmail_quote">On Sun, Apr 5, 2009 at 8:47 AM, gigli <span dir="ltr">&lt;<a href="mailto:gigli@swipnet.se">gigli@swipnet.se</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">Peter Humphrey skrev:<br>
<div><div></div><div class="h5">&gt; On Sunday 05 April 2009 11:41:55 gigli wrote:<br>
&gt;<br>
&gt;&gt; i will give shorewall a new try and hope i&#39;ll make better progress thsi<br>
&gt;&gt; time<br>
&gt;<br>
&gt; My gateway machine has three interfaces and uses shorewall to protect them.<br>
&gt; If you like I could tar up /etc/shorewall and send it to you. I&#39;ve had to<br>
&gt; create macros for several services and put them in /usr/share/shorewall,<br>
&gt; but if you run &quot;shorewall try /etc/shorewall&quot; it&#39;ll tell you which you<br>
&gt; need. I made them by copying others and changing bits.<br>
&gt;<br>
&gt; The three interfaces are the external network (a DSL modem), the internal<br>
&gt; wired network (an Ethernet switch) and a wireless network (an access<br>
&gt; point).<br>
&gt;<br>
&gt; I don&#39;t suppose my setup is the acme of elegance or wit, but it seems to<br>
&gt; work. The rules file is 195 lines long.<br>
&gt;<br>
</div></div>Hi peter<br>
<br>
I would be happy if you mailed me the tar. I have only one interface and<br>
need to protect my computer while connected through openvpn, i guess<br>
openvpn goes directly through my pfsense box bothways and it would be<br>
nice to stay protected then. Or have i misunderstood that?<br>
<br>
Martin<br>
<font color="#888888"><a href="mailto:gigli@swipnet.se">gigli@swipnet.se</a><br>
<br>
</font></blockquote></div><br>