[Firehol-support] 2.02 and src with multiple IPs - syntax change?

Whit Blauvelt whit at transpect.com
Thu Mar 19 15:22:53 GMT 2015


Syntax that used to work doesn't now:

server ssh accept src,,

results in:

ERROR   : # 1.
WHAT    : A runtime command failed to execute (returned error 2).
SOURCE  : line 16 of /etc/firehol/firehol.conf
COMMAND : /sbin/iptables -t filter -A in_world_ssh_s2 -p tcp -s\,\,\ --sport 1024:65535 --dport 22 -m conntrack --ctstate NEW\,ESTABLISHED -j ACCEPT 

iptables v1.4.4: host/network `,,' not found
Try `iptables -h' or 'iptables --help' for more information.

Removing the commas gives:

ERROR #: 1
WHAT   : Rules for ssh server, with server port(s) 'tcp/22' and client port(s) 'default'
WHY    : Cannot understand directive ''.
COMMAND: server ssh accept src 
MODE   : both
SOURCE : line 16 of /etc/firehol/firehol.conf

Don't know if the second ever worked, but the first surely did. Looks like
inappropriate escaping.



More information about the Firehol-support mailing list