12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

498CHAPTER 24Configuring a FirewallROUTEThe error message sent back depends on the type chosen. The icmp-port-unreachabletype is the default. Valid types: icmp-net-unreachable, icmp-host-unreachable,icmp-port-unreachable, icmp-proto-unreachable, icmp-net-prohibited,icmp-host-prohibited, icmp-admin-prohibitedChange the default routing. Must be used with the mangle table.--oif Route through the defined NIC.--iif Modify incoming interface of packet to defined NIC.--gw Route the packet through the defined gateway.--continueAct like a nonterminating target and keep processing the rules. Can’t be usedwith --iif or --tee.--teeRoute a copy of the packet to the given destination. The original packet acts likea nonterminating target and keeps processing the rules. Can’t be used with--iif or --continue.SAMEGives each client the same source and destination address for each connection basedon a range.--to -Range of IP address to use.--nodstWhen calculating the source address, don’t take the destination address intoconsideration.SETAdd or delete from IP sets defined by ipset.--add-set Add addresses or ports to the named set. is a comma-separated list, whichcan be src and/or dst.--del-set Delete addresses or ports to the named set. is a comma-separated list,which can be src and/or dst.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!