ich versuche gerade einen squid proxy u. die shorewall firewall zu konfigurieren.
ich geht nach dem howto von :http://www.slixs.at/web/dokus/sarge/shorewall.htm vor.
Hat bis jetzt auch alles super geklappt, nur startet die Firewall nicht... wenn ich unter Webmin den Firewall check mache kommt folgende fehlermeldung:
Code: Alles auswählen
Checking configuration ..
Loading /usr/share/shorewall/functions...
Processing /etc/shorewall/shorewall.conf...
Loading Modules...
Shorewall has detected the following iptables/netfilter capabilities:
NAT: Available
Packet Mangling: Available
Multi-port Match: Available
Extended Multi-port Match: Not available
Connection Tracking Match: Available
Packet Type Match: Available
Policy Match: Not available
Physdev Match: Available
IP range Match: Available
Recent Match: Available
Verifying Configuration...
Determining Zones...
Zones: net loc
Validating interfaces file...
Validating hosts file...
Determining Hosts in Zones...
net Zone: eth1:0.0.0.0/0
Warning: Zone loc is empty
Validating policy file...
Policy for loc to net is ACCEPT using chain loc2all
Policy for loc to fw is ACCEPT using chain loc2all
Policy for net to loc is DROP using chain net2all
Policy for net to fw is DROP using chain net2all
Pre-validating Actions...
Pre-processing /usr/share/shorewall/action.DropSMB...
Pre-processing /usr/share/shorewall/action.RejectSMB...
Pre-processing /usr/share/shorewall/action.DropUPnP...
Pre-processing /usr/share/shorewall/action.RejectAuth...
Pre-processing /usr/share/shorewall/action.DropPing...
Pre-processing /usr/share/shorewall/action.DropDNSrep...
Pre-processing /usr/share/shorewall/action.AllowPing...
Pre-processing /usr/share/shorewall/action.AllowFTP...
Pre-processing /usr/share/shorewall/action.AllowDNS...
Pre-processing /usr/share/shorewall/action.AllowSSH...
Pre-processing /usr/share/shorewall/action.AllowWeb...
Pre-processing /usr/share/shorewall/action.AllowSMB...
Pre-processing /usr/share/shorewall/action.AllowAuth...
Pre-processing /usr/share/shorewall/action.AllowSMTP...
Pre-processing /usr/share/shorewall/action.AllowPOP3...
Pre-processing /usr/share/shorewall/action.AllowICMPs...
Pre-processing /usr/share/shorewall/action.AllowIMAP...
Pre-processing /usr/share/shorewall/action.AllowTelnet...
Pre-processing /usr/share/shorewall/action.AllowVNC...
Pre-processing /usr/share/shorewall/action.AllowVNCL...
Pre-processing /usr/share/shorewall/action.AllowNTP...
Pre-processing /usr/share/shorewall/action.AllowRdate...
Pre-processing /usr/share/shorewall/action.AllowNNTP...
Pre-processing /usr/share/shorewall/action.AllowTrcrt...
Pre-processing /usr/share/shorewall/action.AllowSNMP...
Pre-processing /usr/share/shorewall/action.AllowPCA...
Pre-processing /usr/share/shorewall/action.AllowSPAMD...
Pre-processing /usr/share/shorewall/action.AllowSyslog...
Pre-processing /usr/share/shorewall/action.AllowAmanda...
Pre-processing /usr/share/shorewall/action.AllowLDAP...
Pre-processing /usr/share/shorewall/action.AllowICQ...
Pre-processing /usr/share/shorewall/action.AllowBitTorrent...
Pre-processing /usr/share/shorewall/action.AllowSMBswat...
Pre-processing /usr/share/shorewall/action.DropSMTP...
Pre-processing /usr/share/shorewall/action.AllowCVS...
Pre-processing /usr/share/shorewall/action.AllowSVN...
Pre-processing /usr/share/shorewall/action.AllowMySQL...
Pre-processing /usr/share/shorewall/action.AllowPostgreSQL...
Pre-processing /usr/share/shorewall/action.AllowRsync...
Pre-processing /usr/share/shorewall/action.AllowDistcc...
Pre-processing /usr/share/shorewall/action.Drop...
Pre-processing /usr/share/shorewall/action.Reject...
Validating rules file...
Rule "ACCEPT loc fw tcp ssh" checked.
Rule "ACCEPT net fw tcp ssh" checked.
Error: No policy defined from zone fw to zone net
.. an error was found in your firewall configuration!
mfg. misterchoc