diff --git a/firewall/help/intro.ca.html b/firewall/help/intro.ca.html index 6c9c2c775..e3feefd09 100644 --- a/firewall/help/intro.ca.html +++ b/firewall/help/intro.ca.html @@ -69,6 +69,24 @@ prendre la configuraci disposici de l'editor. Finalment, si la distribuci ho suporta, hi ha un bot per canviar si el tallafocs s'activa en engegar el sistema o no.

+ + +

Filtering chains

+ +For better collaboration with external iptables scripts you can exclude individual +chains from the processing by the firewall. To do this, you must select direct +processing of rules in the settings and enter a filter list, which excludes +the appropriate chains from processing. +Chains that are not exculded from editing are flagged with a "not managed by firewall" message. +

+ +

IP Sets

+ +Newer versions of ip(6)table support the ipset extension. +IP sets are lists of IP addresses in the main memory, which can be searched very efficiently +and used as a condition in rules. On the main page, existing IP sets that can be used by +rules are displayed. Currently, however, it is not possible to manage these in the firewall. +

+


- diff --git a/firewall/help/intro.de.html b/firewall/help/intro.de.html index fd2a7eabe..07e1533cd 100644 --- a/firewall/help/intro.de.html +++ b/firewall/help/intro.de.html @@ -69,5 +69,20 @@ Schließlich gibt noch eine Schaltfläche, um zu einzustellen ob die Fi Bootens aktiviert wird oder nicht.

+

Filtern von Ketten

+ +Für die bessere Zusammenarbeit mit exernen IPtables Scripten kann man einzelne Ketten von +der Bearbeitung durch die Firewall ausnehmen. Dazu müssen sie in den Einstellungen die direkte +Bearbeitung von Regeln auswählen und eine Filterliste +eingeben, welche die passenden Ketten von der Bearbeitung ausnimmt. +Ketten die nicht bearbeitet werden mit dem Hinweis "nichit von Firewall verwaltet" angezeigt

+ +

IP-Sets

+ +Neuere Versionen von IPtable unterstützen die Erweiterung ipset. IP-Sets sind Listen von IP-Adressen +im Hauptspeicher, die sehr effizient durchsucht und als Bedingung in Regeln verwendet werden können. +Auf der Hauptseite werden vorhandene IP-Sets die von der Regeln verwendet werden können angezeigt. +Derzeit ist es allerdings nicht möglich diese in der Firewall zu verwalten. +
diff --git a/firewall/help/intro.html b/firewall/help/intro.html index 3d6d5934c..9bc1122a8 100644 --- a/firewall/help/intro.html +++ b/firewall/help/intro.html @@ -68,5 +68,22 @@ taking the configuration that is currently in the kernel and making it available for editing. Finally, if your distribution supports it, there is a button to change whether the firewall is activated at boot time or not.

+

Filtering chains

+ +For better collaboration with external iptables scripts you can exclude individual +chains from the processing by the firewall. To do this, you must select direct +processing of rules in the settings and enter a filter list, which excludes +the appropriate chains from processing. +Chains that are not exculded from editing are flagged with a "not managed by firewall" message. +

+ +

IP Sets

+ +Newer versions of ip(6)table support the ipset extension. +IP sets are lists of IP addresses in the main memory, which can be searched very efficiently +and used as a condition in rules. On the main page, existing IP sets that can be used by +rules are displayed. Currently, however, it is not possible to manage these in the firewall. +

+


diff --git a/firewall/help/intro.nl.html b/firewall/help/intro.nl.html index 6a3f09b73..fe2b4f654 100644 --- a/firewall/help/intro.nl.html +++ b/firewall/help/intro.nl.html @@ -75,5 +75,23 @@ vervolgens kunt bewerken. Tot slot, indien uw distributie dit ondersteund is er ook een knop waarmee u kunt wijzigen of de firewall wel of niet tijdens het booten geactiveerd moet worden.

-


+

Filtering chains

+ +For better collaboration with external iptables scripts you can exclude individual +chains from the processing by the firewall. To do this, you must select direct +processing of rules in the settings and enter a filter list, which excludes +the appropriate chains from processing. +Chains that are not exculded from editing are flagged with a "not managed by firewall" message. +

+ +

IP Sets

+ +Newer versions of ip(6)table support the ipset extension. +IP sets are lists of IP addresses in the main memory, which can be searched very efficiently +and used as a condition in rules. On the main page, existing IP sets that can be used by +rules are displayed. Currently, however, it is not possible to manage these in the firewall. +

+ +


+ diff --git a/firewall/help/intro.pl.html b/firewall/help/intro.pl.html index 391121356..61ae69890 100644 --- a/firewall/help/intro.pl.html +++ b/firewall/help/intro.pl.html @@ -68,5 +68,23 @@ edycj funkcj znajduje si przycisk umoliwiajcy wybranie, czy firewall ma by aktywowany w momencie uruchamiania systemu czy nie.

-


+

Filtering chains

+ +For better collaboration with external iptables scripts you can exclude individual +chains from the processing by the firewall. To do this, you must select direct +processing of rules in the settings and enter a filter list, which excludes +the appropriate chains from processing. +Chains that are not exculded from editing are flagged with a "not managed by firewall" message. +

+ +

IP Sets

+ +Newer versions of ip(6)table support the ipset extension. +IP sets are lists of IP addresses in the main memory, which can be searched very efficiently +and used as a condition in rules. On the main page, existing IP sets that can be used by +rules are displayed. Currently, however, it is not possible to manage these in the firewall. +

+ +


+ diff --git a/firewall/help/intro.pt_BR.html b/firewall/help/intro.pt_BR.html index b7ea0bc7b..77e847bd6 100644 --- a/firewall/help/intro.pt_BR.html +++ b/firewall/help/intro.pt_BR.html @@ -35,5 +35,23 @@ Voc Na parte de baixo da pgina est um boto para tornar a configurao atual do firewall ativa, carregando-a atravs do comando ipi(6)tables-restore. A seguir est um boto para fazer o inverso - pegar a configurao que est corrente no kernel e torn-la disponvel para edio. Finalmente, se sua distribuio suportar, existe um boto para indicar se o firewall ser ativado durante o boot ou no.

-


+

Filtering chains

+ +For better collaboration with external iptables scripts you can exclude individual +chains from the processing by the firewall. To do this, you must select direct +processing of rules in the settings and enter a filter list, which excludes +the appropriate chains from processing. +Chains that are not exculded from editing are flagged with a "not managed by firewall" message. +

+ +

IP Sets

+ +Newer versions of ip(6)table support the ipset extension. +IP sets are lists of IP addresses in the main memory, which can be searched very efficiently +and used as a condition in rules. On the main page, existing IP sets that can be used by +rules are displayed. Currently, however, it is not possible to manage these in the firewall. +

+ +


+ diff --git a/firewall/help/intro.ru.UTF-8.html b/firewall/help/intro.ru.UTF-8.html index 188789d12..08b2ecd7c 100644 --- a/firewall/help/intro.ru.UTF-8.html +++ b/firewall/help/intro.ru.UTF-8.html @@ -40,5 +40,23 @@ При попытке добавить или отредактировать правило, откроется новая страница на которой вы сможете выбрать Действие для правила, а так же Условие, при котором это Действие должно выполняться.

В самом низу главной страницы находятся несколько кнопок: Применить конфигурацию - активирует текущие настройки брандмауэра, загружая их в ядро командой ipi(6)tables-restore. Вернуть конфигурацию действует наоборот - загружает в окно для конфигурирования настройки, активные в данный момент в ядре. Включать при запуске позволяет настроить автозапуск брандмауэра (если поддерживается вашим дистрибутивом). Сбросить конфигурацию - очищает все цепочки и таблицы, чтобы начать настройку с нуля.

-


+

Filtering chains

+ +For better collaboration with external iptables scripts you can exclude individual +chains from the processing by the firewall. To do this, you must select direct +processing of rules in the settings and enter a filter list, which excludes +the appropriate chains from processing. +Chains that are not exculded from editing are flagged with a "not managed by firewall" message. +

+ +

IP Sets

+ +Newer versions of ip(6)table support the ipset extension. +IP sets are lists of IP addresses in the main memory, which can be searched very efficiently +and used as a condition in rules. On the main page, existing IP sets that can be used by +rules are displayed. Currently, however, it is not possible to manage these in the firewall. +

+ +


+ diff --git a/firewall/help/intro.sk.html b/firewall/help/intro.sk.html index c6b881663..3145e3a42 100644 --- a/firewall/help/intro.sk.html +++ b/firewall/help/intro.sk.html @@ -63,5 +63,23 @@ vezme konfigur podporuje, je tu ete tlaidlo, ktor nastav, i sa m firewall aktivova pri zavdzan systmu alebo nie.

-


+

Filtering chains

+ +For better collaboration with external iptables scripts you can exclude individual +chains from the processing by the firewall. To do this, you must select direct +processing of rules in the settings and enter a filter list, which excludes +the appropriate chains from processing. +Chains that are not exculded from editing are flagged with a "not managed by firewall" message. +

+ +

IP Sets

+ +Newer versions of ip(6)table support the ipset extension. +IP sets are lists of IP addresses in the main memory, which can be searched very efficiently +and used as a condition in rules. On the main page, existing IP sets that can be used by +rules are displayed. Currently, however, it is not possible to manage these in the firewall. +

+ +


+ diff --git a/firewall/help/ipset.txt b/firewall/help/ipset.txt new file mode 100644 index 000000000..92d68945b --- /dev/null +++ b/firewall/help/ipset.txt @@ -0,0 +1,19 @@ +

Filtering chains

+ +For better collaboration with external iptables scripts you can exclude individual +chains from the processing by the firewall. To do this, you must select direct +processing of rules in the settings and enter a filter list, which excludes +the appropriate chains from processing. +Chains that are not exculded from editing are flagged with a "not managed by firewall" message. +

+ +

IP Sets

+ +Newer versions of ip(6)table support the ipset extension. +IP sets are lists of IP addresses in the main memory, which can be searched very efficiently +and used as a condition in rules. On the main page, existing IP sets that can be used by +rules are displayed. Currently, however, it is not possible to manage these in the firewall. +

+ +


+