Hi I can''t surf on the net coz I can''t connect to my dns servers although my policy is the right one that is to say: fw net ACCEPT Here is a extract of my logs which illustrates the problem: Chain OUTPUT (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 0 0 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0 I think that here it might not be lo but net and my problem is that I can''t find out how to solve that Could anyone tell me where I make a mistake? Thx Btw: I''ve used the defaults files that are stored in one-interface.tar.gz
On Fri, 28 Nov 2003, Guillaume R. wrote:> Hi > I can''t surf on the net coz I can''t connect to my dns servers although > my policy is the right one that is to say: > fw net ACCEPT > > Here is a extract of my logs which illustrates the problem: > > Chain OUTPUT (policy DROP 0 packets, 0 bytes) > pkts bytes target prot opt in out source destination > 0 0 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0 > > I think that here it might not be lo but net and my problem is that I can''t find out how to > solve that > Could anyone tell me where I make a mistake? > Thx > Btw: I''ve used the defaults files that are stored in one-interface.tar.gz >And did you modify them to fit your particular configuration as described at http://www.shorewall.net/standalone.htm? -Tom -- Tom Eastep \ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ teastep@shorewall.net
On Fri, 28 Nov 2003, Guillaume R. wrote:> Hi > I can''t surf on the net coz I can''t connect to my dns servers although > my policy is the right one that is to say: > fw net ACCEPT > > Here is a extract of my logs which illustrates the problem: > > Chain OUTPUT (policy DROP 0 packets, 0 bytes) > pkts bytes target prot opt in out source destination > 0 0 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0 > > I think that here it might not be lo but net and my problem is that I can''t find out how to > solve that > Could anyone tell me where I make a mistake?Also, what happens when as root you issue the following command? /sbin/shorewall start -Tom -- Tom Eastep \ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ teastep@shorewall.net