shorewall-users September 2010 archive
Main Archive Page > Month Archives  > shorewall-users archives
shorewall-users: Re: [Shorewall-users] SECMARK and CONNSECMARK s

Re: [Shorewall-users] SECMARK and CONNSECMARK support in Shorewall

From: Mr Dash Four <mr.dash.four_at_nospam>
Date: Sun Sep 05 2010 - 16:32:43 GMT
To: Tom Eastep <teastep@shorewall.net>, Shorewall Users <shorewall-users@lists.sourceforge.net>

Hi, Tom,

Further to my previous post, I managed to load my ipsets manually
(through a shell script), but shorewall still refuses to start and I get
the following error:

ERROR: An ipset name (+blacklist-chinese-banned) is not allowed in this
context: /etc/shorewall/blacklist (line 11)

The line in question in my blacklist file contains this:

+blacklist-chinese-banned - - to

There are about 8 lines similar to this, though the above is the first
one. What's wrong? I had this working before, though I adopted the new
syntax (with the 'to'/'from' options) and changed to the above format.

------------------------------------------------------------------------------
This SF.net Dev2Dev email is sponsored by:

Show off your parallel programming skills.
Enter the Intel(R) Threading Challenge 2010.
http://p.sf.net/sfu/intel-thread-sfd
_______________________________________________
Shorewall-users mailing list
Shorewall-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-users