Horst Knobloch <(E-Mail Removed)> wrote:
> Why don't you put these two command into some boot-up scripts
> eg. rc.local and just try it? Good crafted packet filter scripts
> can be setup without an existing ppp interface.
I don't see any way that net-filtering could be successfully started
without the PPP interface, and the interface doesn't come up until
the IPCP negotiations for the PPP link are completed. Can you give
us example of how to start net-filtering without the interface?
> If shorewall does rely on the ppp interface to exist, you can
> put your 2 commands into the /etc/ppp/ip-up.local script. This
> script is called when the ppp interface has come up. He can
> stop the firewall by putting the appropriate stop command to
> /etc/ppp/ip-down.local.
If the two scripts above exist (it depends on the distribution) then
they are probably the ones to use, but if they don't exist then he can
simply put the commands for the start script in /etc/ppp/ip-up and the
down script in /etc/ppp/ip-down. These scripts are executed by pppd
after the interface is up and after it is down, respectively. He might
have to use the full path name for the scripts, depending on what PATH
is set for the scripts.
--
Clifford Kite Email: "echo
xvgr_yvahk-(E-Mail Removed)|rot13"
PPP-Q&A links, downloads:
http://ckite.no-ip.net/
/* "Be liberal in what you accept, and conservative in what you send"
RFC 1122 */