Question about virtual interface

Tony Peña <[email protected]>
Newsgroups gmane.comp.security.firewalls.firehol.user
Message-ID <CALBaCdv0rxbam5UefFi80jOcBXdVSXz2yB6jEMJHNZAtWGdgKQ@mail.gmail.com>
Hi,...
I'm wondering how can i setup a firehol.conf with 1 physical and virtual at
same time
I got now a server outside of my country and is very difficult if i try to
setup iptables security and lost my conex...

I used firehol before, with normal ethernets... eth0 and eth1, but never
with eth0:1,...

So..

i got this...

eth0 and eth0:1 to into server from

internet.......cisco....[real-wan-ip] nat inside eth0....10.x.y.z
internet.......same cisco [real-wan-ip+1] nat inside eth0:1 ....10.x.y.z+1

if i try

interface eth0 phy-net
     policy drop
     server icmp accept
     server ssh accept
     cliente all accept

interface eth0:1 virt-net
    policy drop
    server icmp accept
    server ssh accept
    client all accept


i can't hit with icmp / ssh ping to eth0 or eth0:1...

for other reason i need to use this eth0:1 to can use other service running
on there.
any help will be appreciated...
my server is only supported now by fail2ban, to try keeping out attacks...
missing my firehol.conf to defender more harder..

question: if I type firehol try, and still can't commit the changes.. is
very secure to recover my conex if before my ssh is restore because have
now 0 rules applied ?

Thanxs in advance




-- 
Antonio Peña
Secure email with PGP 0x8B021001 available at http://pgp.mit.edu
Fingerprint: 74E6 2974 B090 366D CE71  7BB2 6476 FA09 8B02 1001

------------------------------------------------------------------------------
Try New Relic Now & We'll Send You this Cool Shirt
New Relic is the only SaaS-based application performance monitoring service 
that delivers powerful full stack analytics. Optimize and monitor your
browser, app, & servers with just a few lines of code. Try New Relic
and get this awesome Nerd Life shirt! http://p.sf.net/sfu/newrelic_d2d_apr

_______________________________________________
Firehol-support mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/firehol-support
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.