theatereleven wrote:
The docs say in Lenny to copy all of the files from user/share/doc/shorewall-common/default-config to my /etc/shorewall folder - am I reading this right?
Thanks again man.
I don't know if you're reading it right, I'm perfectly happy with Arno's firewall.

But I wouldn't be surprised if they were saying something in style of "The debian default is to (block|allow) everything. To get a config like when you install shorewall from source, copy the default-config files to /etc.". Just read them until they make sense...
And no problem...
no problem...
(Good luck!)
PS. vonskippy... I know you like to state your opinions aggressively... but please... cut it down a bit... I agree, partially - a big package like shorewall doesn't seem necessary. On the other hand, "raw" iptables is quite a bit of manual work, and if you're a newb like me and the OP, it's quite dangerous to mess with.
That's why I'd actually recommend going with arno's, which has been linked above. It's not much more than a nice SIMPLE debconf-configurable frontend to iptables, with really nice throttled logging.