summaryrefslogtreecommitdiff
path: root/docs/configexamples/zone-policy.rst
diff options
context:
space:
mode:
authorRobert Göhler <github@ghlr.de>2021-06-30 14:49:40 +0200
committerGitHub <noreply@github.com>2021-06-30 14:49:40 +0200
commite58574d80d49d11dba556c8cb3653310a94fc50d (patch)
tree1e4ae8324f21f89178e454af29172ca36b9552fc /docs/configexamples/zone-policy.rst
parentae6a2ba810a19d81cbad5b0da29e791a7b5e411f (diff)
parent10737cad913c17e3cce7291dcd835999f16459a2 (diff)
downloadvyos-documentation-e58574d80d49d11dba556c8cb3653310a94fc50d.tar.gz
vyos-documentation-e58574d80d49d11dba556c8cb3653310a94fc50d.zip
Merge branch 'master' into misc
Diffstat (limited to 'docs/configexamples/zone-policy.rst')
-rw-r--r--docs/configexamples/zone-policy.rst6
1 files changed, 4 insertions, 2 deletions
diff --git a/docs/configexamples/zone-policy.rst b/docs/configexamples/zone-policy.rst
index bfe77c2e..cf11a01e 100644
--- a/docs/configexamples/zone-policy.rst
+++ b/docs/configexamples/zone-policy.rst
@@ -1,3 +1,5 @@
+:lastproofread: 2021-06-29
+
.. _examples-zone-policy:
Zone-Policy example
@@ -132,7 +134,7 @@ To add logging to the default rule, do:
set firewall name <ruleSet> enable-default-log
-By default, iptables does not allow traffic for established session to
+By default, iptables does not allow traffic for established sessions to
return, so you must explicitly allow this. I do this by adding two rules
to every ruleset. 1 allows established and related state packets through
and rule 2 drops and logs invalid state packets. We place the
@@ -367,7 +369,7 @@ IPv6 Tunnel
^^^^^^^^^^^
If you are using a IPv6 tunnel from HE.net or someone else, the basis is
-the same except you have two WAN interface. One for v4 and one for v6.
+the same except you have two WAN interfaces. One for v4 and one for v6.
You would have 5 zones instead of just 4 and you would configure your v6
ruleset between your tunnel interface and your LAN/DMZ zones instead of