Displaying 20 results from an estimated 29 matches for "adminisabsentminded".
2014 Feb 28
0
ADMINISABSENTMINDED=No misbehaviour according to the manual
Hello.
I'm getting trouble with the ADMINISABSENTMINDED option, it doesn't seem
to work as stated in the manual.
When using the default ADMINISABSENTMINDED=Yes and no routestopped file,
here are the firewall state after executing shorewall stop :
Chain INPUT (policy DROP 473 packets, 106K bytes)
pkts bytes target prot opt in...
2013 Oct 27
4
shorewall stop
hi, while stopping shorewall 4.5.21.2 on a debian7 box with the
ADMINISABSENTMINDED set to no in shorewall.conf, the connections on
vlan tagged interfaces that were active before the shorewall stop
command was executed are not terminated as it is for the firewall and
other interfaces!
when the firewall is stopped as expected new connections on vlan
tagged interface are refuse...
2005 Feb 23
13
Snort and Shorewall
Hello
I am looking for a way to have snort to dynamically update my shorewall config.
I have seen software out there but I would like to see if anyone had tried this
first.
Aslo I would like to know if there is a way clear the Netfilter tables when I do
a shorewall restart. The reason being is that when I make a change to my
firewall setting I want all connections to have to re-establish
2005 Jan 07
6
Questions: place for doco, and routestopped during ''shorewall restart''
...handles traffic during a
''shorewall restart'': i''ve found that whenever i do this on one of my
clustered firewalls, i get a huge number of errors in syslog relating
to heartbeat timeouts. I''ve got the other cluster node in the
routestopped file on both nodes, and ADMINISABSENTMINDED=Yes in
shorewall.conf, but it still gives me errors like these:
Jan 7 10:10:13 fwA heartbeat[13997]: ERROR: Error sending packet:
Operation not permitted
Jan 7 10:10:13 fwA heartbeat[13997]: ERROR: write failure on ping
192.168.0.43.: Operation not permitted
Jan 7 10:10:14 fwA heartbeat[13991]:...
2005 Mar 15
5
unable to filter or log vpn traffic
hi all,
i have a classic net topology with two local zone, a firewall/router
with dsl connection
loc1 (192.168.11.0/24)
----- fw ----- net
loc2 (192.168.12.0/24)
now on the local zone 1 (on a WinXP machine) i have installed
OpenVPN 2.x to make a test connection with a company.
OpenVPN is configured as client to use tun on udp
port 10000 with ip 10.0.0.2, on the other
2003 Aug 09
0
Snapshot 20030809
...;' and ''reject'' used to do; namely, when an address
is blacklisted using these new commands, it will be blacklisted on
all of your firewall''s interfaces.
2) Thanks to Steve Herber, the help command can now give
command-specific help.
3) A new option "ADMINISABSENTMINDED" has been added to
/etc/shorewall/shorewall.conf. This option has a default value of
"No" for existing Shorewall users who are upgrading to this release.
With this setting, Shorewall''s ''stopped'' state continues as it has
been; namely, in the sto...
2003 Jul 31
0
Snapshot 1.4.6_20030731
...e Herber, the help command can now give
command-specific help.
3) The "shorewall stop" command is now disabled when
/etc/shorewall/startup_disabled exists. This prevents people from
shooting themselves in the foot prior to having configured
Shorewall.
4) A new option "ADMINISABSENTMINDED" has been added to
/etc/shorewall/shorewall.conf. For existing users, this option has a
default value of "No" in which case Shorewall''s ''stopped'' state
continues as it has been; namely, in the stopped state only traffic
to/from hosts listed in...
2004 Apr 24
4
Debian Package Behavior Suggestion
...nstable tree. This was on the www.shorewall.net mirror server.
And, to my horror, after upgrading the package, it automatically restarted
shorewall!
Of course I have done this before, but I absent-mindedly just went through
the usual procedure for debian upgrades without thinking about it. (note:
adminisabsentminded=yes in shorewall.conf :)
Luckily, no side effects, as it was a 2.0.0(x-1) - 2.0.0(x) upgrade. I do
know that auto restarts are the usual behavior for most debian packaged
services, but many prompt for authorization.
So anyways, maybe it might be safer to prompt for a restart, or simply to
post a...
2003 Aug 25
5
Shorewall 1.4.7 Beta 1
...atic, the ''dropunclean'' and
''logunclean'' interface options will be removed in a future
release. In the 1.4.7 release, they are flagged with a warning.
2) Thanks to Steve Herber, the help command can now give
command-specific help.
3) A new option "ADMINISABSENTMINDED" has been added to
/etc/shorewall/shorewall.conf. This option has a default value of
"No" for existing Shorewall users who are upgrading to this release.
With this setting, Shorewall''s ''stopped'' state continues as it has
been; namely, in the sto...
2003 Aug 22
0
Snapshot 20030821
...39;' and ''reject'' used to do; namely, when an address
is blacklisted using these new commands, it will be blacklisted on
all of your firewall''s interfaces.
2) Thanks to Steve Herber, the help command can now give
command-specific help.
3) A new option "ADMINISABSENTMINDED" has been added to
/etc/shorewall/shorewall.conf. This option has a default value of
"No" for existing Shorewall users who are upgrading to this release.
With this setting, Shorewall''s ''stopped'' state continues as it has
been; namely, in the sto...
2003 Aug 13
0
Snapshot 1.4.6 20030813
...39;' and ''reject'' used to do; namely, when an address
is blacklisted using these new commands, it will be blacklisted on
all of your firewall''s interfaces.
2) Thanks to Steve Herber, the help command can now give
command-specific help.
3) A new option "ADMINISABSENTMINDED" has been added to
/etc/shorewall/shorewall.conf. This option has a default value of
"No" for existing Shorewall users who are upgrading to this release.
With this setting, Shorewall''s ''stopped'' state continues as it has
been; namely, in the sto...
2003 Oct 06
2
Shorewall 1.4.7
...atic, the ''dropunclean'' and
''logunclean'' interface options will be removed in a future
release. In the 1.4.7 release, they are flagged with a warning.
2) Thanks to Steve Herber, the help command can now give
command-specific help.
3) A new option "ADMINISABSENTMINDED" has been added to
/etc/shorewall/shorewall.conf. This option has a default value of
"No" for existing Shorewall users who are upgrading to this release.
With this setting, Shorewall''s ''stopped'' state continues as it has
been; namely, in the sto...
2008 Dec 31
5
"ERROR: Unknown host - any host" My configuration suddenly don't work, why?
Hi, i have been using shorewall for 3 months, and shorewall was working
well, but i don''t know why, when I type "shorewall start" o "shorewall
restart", it says that.
I have two files of rules:
The first:
DNS/ACCEPT net:208.67.222.222,208.67.220.220
The second:
DNS/ACCEPT net:208.67.222.222,208.67.220.220
HTTP/ACCEPT net:www.google.com,mail.google.com,...
2005 Mar 10
7
norfc1918 not working in SW 2.2.1?
...ULESDIR=
CONFIG_PATH=/etc/shorewall/action:/etc/shorewall/custom:/etc/shorewall:/usr/share/shorewall
FW=fw
IP_FORWARDING=Off
ADD_IP_ALIASES=Yes
ADD_SNAT_ALIASES=No
TC_ENABLED=Yes
CLEAR_TC=Yes
MARK_IN_FORWARD_CHAIN=No
CLAMPMSS=No
ROUTE_FILTER=Yes
DETECT_DNAT_IPADDRS=No
MUTEX_TIMEOUT=60
NEWNOTSYN=Yes
ADMINISABSENTMINDED=No
BLACKLISTNEWONLY=No
MODULE_SUFFIX=
DISABLE_IPV6=No
BRIDGING=No
DYNAMIC_ZONES=No
BLACKLIST_DISPOSITION=DROP
MACLIST_DISPOSITION=REJECT
TCP_FLAGS_DISPOSITION=DROP
[root@hn00dmz01 root]# ip addr show
1: lo: <LOOPBACK,UP> mtu 16436 qdisc noqueue
link/loopback 00:00:00:00:00:00 brd 00:00:...
2008 Nov 13
4
ERROR: Unknown Host (All hosts) : /usr/share/shorewall/macro.Any macro or rule
Hi. I set, for example, a rule with a host server:
Macro.http accept fw net:www.google.es
I restart shorewall and it works, but when i stop the firewall for
disabling Internet (for any reason), and i want start the firewall it
says:
Failed to start firewall :
Compiling...
Compiling /etc/shorewall/zones...
Compiling /etc/shorewall/interfaces...
WARNING: Support for the detectnets interface
2008 Nov 13
4
ERROR: Unknown Host (All hosts) : /usr/share/shorewall/macro.Any macro or rule
Hi. I set, for example, a rule with a host server:
Macro.http accept fw net:www.google.es
I restart shorewall and it works, but when i stop the firewall for
disabling Internet (for any reason), and i want start the firewall it
says:
Failed to start firewall :
Compiling...
Compiling /etc/shorewall/zones...
Compiling /etc/shorewall/interfaces...
WARNING: Support for the detectnets interface
2006 Aug 29
3
masq problem
...ot;
MODULESDIR=
CONFIG_PATH=/etc/shorewall:/usr/share/shorewall
RESTOREFILE=
IPSECFILE=zones
FW=
IP_FORWARDING=Keep
ADD_IP_ALIASES=Yes
ADD_SNAT_ALIASES=No
RETAIN_ALIASES=No
TC_ENABLED=Internal
CLEAR_TC=Yes
MARK_IN_FORWARD_CHAIN=No
CLAMPMSS=No
ROUTE_FILTER=Yes
DETECT_DNAT_IPADDRS=No
MUTEX_TIMEOUT=60
ADMINISABSENTMINDED=Yes
BLACKLISTNEWONLY=Yes
DELAYBLACKLISTLOAD=No
MODULE_SUFFIX=
DISABLE_IPV6=Yes
BRIDGING=No
DYNAMIC_ZONES=No
PKTTYPE=Yes
RFC1918_STRICT=No
MACLIST_TABLE=filter
MACLIST_TTL=
SAVE_IPSETS=No
MAPOLDACTIONS=No
FASTACCEPT=No
BLACKLIST_DISPOSITION=DROP
MACLIST_DISPOSITION=REJECT
TCP_FLAGS_DISPOSITION=DROP...
2007 Nov 10
2
Access Point with Ethernet.
...b/shorewall
MODULESDIR=
CONFIG_PATH=/etc/shorewall:/usr/share/shorewall
RESTOREFILE=
FW=fw
IP_FORWARDING=On
ADD_IP_ALIASES=Yes
ADD_SNAT_ALIASES=No
RETAIN_ALIASES=No
TC_ENABLED=No
CLEAR_TC=Yes
MARK_IN_FORWARD_CHAIN=No
CLAMPMSS=No
ROUTE_FILTER=Yes
DETECT_DNAT_IPADDRS=No
MUTEX_TIMEOUT=60
NEWNOTSYN=Yes
ADMINISABSENTMINDED=Yes
BLACKLISTNEWONLY=Yes
DELAYBLACKLISTLOAD=No
MODULE_SUFFIX=
DISABLE_IPV6=No
BRIDGING=No
DYNAMIC_ZONES=No
PKTTYPE=Yes
DROPINVALID=Yes
RFC1918_STRICT=No
MACLIST_TTL=
BLACKLIST_DISPOSITION=DROP
MACLIST_DISPOSITION=REJECT
TCP_FLAGS_DISPOSITION=DROP
/etc/shorewall/start:
(not configured)
/etc/shore...
2005 Apr 19
14
allow ssh access from net to fw?
...STATEDIR=/var/lib/shorewall
MODULESDIR=
CONFIG_PATH=/etc/shorewall:/usr/share/shorewall
RESTOREFILE=
FW=fw
IP_FORWARDING=On
ADD_IP_ALIASES=Yes
ADD_SNAT_ALIASES=No
TC_ENABLED=No
CLEAR_TC=Yes
MARK_IN_FORWARD_CHAIN=No
CLAMPMSS=yes
ROUTE_FILTER=Yes
DETECT_DNAT_IPADDRS=No
MUTEX_TIMEOUT=60
NEWNOTSYN=Yes
ADMINISABSENTMINDED=Yes
BLACKLISTNEWONLY=Yes
MODULE_SUFFIX=
DISABLE_IPV6=No
BRIDGING=No
DYNAMIC_ZONES=No
PKTTYPE=Yes
BLACKLIST_DISPOSITION=DROP
MACLIST_DISPOSITION=REJECT
TCP_FLAGS_DISPOSITION=DROP
#LAST LINE -- DO NOT REMOVE
START:
----------------------------------------------------------------------------
-------...
2009 Jun 27
1
Transparent Proxy Problem with Squid3 and Shorewall
...9;'
RCP_COMMAND=''scp ${files} ${root}@${system}:${destination}''
IP_FORWARDING=On
ADD_IP_ALIASES=Yes
ADD_SNAT_ALIASES=No
RETAIN_ALIASES=No
TC_ENABLED=Internal
TC_EXPERT=No
CLEAR_TC=Yes
MARK_IN_FORWARD_CHAIN=No
CLAMPMSS=No
ROUTE_FILTER=Yes
DETECT_DNAT_IPADDRS=No
MUTEX_TIMEOUT=60
ADMINISABSENTMINDED=Yes
BLACKLISTNEWONLY=Yes
DELAYBLACKLISTLOAD=No
MODULE_SUFFIX=
DISABLE_IPV6=Yes
BRIDGING=No
DYNAMIC_ZONES=No
PKTTYPE=Yes
RFC1918_STRICT=No
MACLIST_TABLE=filter
MACLIST_TTL=
SAVE_IPSETS=No
MAPOLDACTIONS=No
FASTACCEPT=No
IMPLICIT_CONTINUE=Yes
HIGH_ROUTE_MARKS=No
USE_ACTIONS=Yes
OPTIMIZE=0
EXPORTPARAMS...