Displaying 14 results from an estimated 14 matches for "allowicmps".
2013 Jun 28
0
IPv6 two or more providers, duplicating routing table does not work
...hecking /etc/shorewall6/masq...
Checking MAC Filtration -- Phase 1...
Checking /etc/shorewall6/rules...
Checking /etc/shorewall6/conntrack...
Checking MAC Filtration -- Phase 2...
Applying Policies...
Checking /usr/share/shorewall6/action.Drop for chain Drop...
Checking /usr/share/shorewall6/action.AllowICMPs for chain AllowICMPs...
Checking /usr/share/shorewall6/action.Broadcast for chain Broadcast...
Shorewall6 configuration verified
root@xxxx:/etc/shorewall6# shorewall6 restart
Compiling...
Processing /etc/shorewall6/params ...
Processing /etc/shorewall6/shorewall6.conf...
Loading Modules...
Compilin...
2005 May 31
11
More Tests for 2.4.0-RC2 - strange behaviour
...39; xAllowSMTP = xINCLUDE '']''
+ echo ''AllowSMTP #Allow SMTP (Email)''
+ read first rest
+ ''['' xAllowPOP3 = xINCLUDE '']''
+ echo ''AllowPOP3 #Allow reading mail via POP3''
+ read first rest
+ ''['' xAllowICMPs = xINCLUDE '']''
+ echo ''AllowICMPs #Allows critical ICMP types''
+ read first rest
+ ''['' xAllowIMAP = xINCLUDE '']''
+ echo ''AllowIMAP #Allow reading mail via IMAP''
+ read first rest
+ ''['' xAllow...
2005 Jun 24
6
Is it that difficult?
Hello,
You will find in attachment the layout of my
current physical configuration.
For now, the Cable ISP is not used. Since it
is a dynamic ISP, my mailserver is rejected and
my domain name registers on blacklists like ORDB
and al.
I want it to be used as a default gateway except
for my mail server that would be seen as coming
from my "honest" ADSL ISP.
Here is
2005 Feb 02
1
Masq errors?
...n.AllowWeb...
Pre-processing /usr/share/shorewall/action.AllowSMB...
Pre-processing /usr/share/shorewall/action.AllowAuth...
Pre-processing /usr/share/shorewall/action.AllowSMTP...
Pre-processing /usr/share/shorewall/action.AllowPOP3...
Pre-processing /usr/share/shorewall/action.AllowICMPs...
Pre-processing /usr/share/shorewall/action.AllowIMAP...
Pre-processing /usr/share/shorewall/action.AllowTelnet...
Pre-processing /usr/share/shorewall/action.AllowVNC...
Pre-processing /usr/share/shorewall/action.AllowVNCL...
Pre-processing /usr/share/shorewall/action.AllowNTP...
2004 Oct 14
0
Shorewall 2.1.11
...-----
Hash: SHA1
http://shorewall.net/pub/shorewall/2.1/shorewall-2.1.11
ftp://shorewall.net/pub/shorewall/2.1/shorewall-2.1.11
In addition to correcting several bugs, this version adds the following
features:
1) The default Drop and Reject actions now invoke the new standard
action ''AllowICMPs''. This new action accepts critical ICMP types:
Type 3 code 4 (fragmentation needed)
Type 11 (TTL exceeded)
2) Explicit control over the kernel''s Martian logging is now provided
using the new ''logmartians'' interface option. If you include
''...
2007 Jul 29
12
Shorewall 4.0.0 + Kernel 2.6.21.5-grsec
...termining Hosts in Zones...
fw (firewall)
wan (ipv4)
eth0:0.0.0.0/0
Preprocessing Action Files...
Pre-processing /usr/share/shorewall/action.Drop...
..Expanding Macro /usr/share/shorewall/macro.Auth...
..End Macro /usr/share/shorewall/macro.Auth
..Expanding Macro /usr/share/shorewall/macro.AllowICMPs...
..End Macro /usr/share/shorewall/macro.AllowICMPs
..Expanding Macro /usr/share/shorewall/macro.SMB...
..End Macro /usr/share/shorewall/macro.SMB
..Expanding Macro /usr/share/shorewall/macro.DropUPnP...
..End Macro /usr/share/shorewall/macro.DropUPnP
..Expanding Macro /usr/share/shorewall/m...
2006 Oct 21
1
Problem with virtual interface
...ng hosts file...
Validating Policy file...
Determining Hosts in Zones...
net Zone: eth0:0.0.0.0/0
Pre-processing Actions...
Pre-processing /usr/share/shorewall/action.Drop...
..Expanding Macro /usr/share/shorewall/macro.Auth...
..End Macro
..Expanding Macro /usr/share/shorewall/macro.AllowICMPs...
..End Macro
..Expanding Macro /usr/share/shorewall/macro.SMB...
..End Macro
..Expanding Macro /usr/share/shorewall/macro.DropUPnP...
..End Macro
..Expanding Macro /usr/share/shorewall/macro.DropDNSrep...
..End Macro
Pre-processing /usr/share/shorewall/action.Reject......
2005 May 31
2
Local machine not through firewall
....0/0
20 1740 fw2loc all -- * eth0 0.0.0.0/0 0.0.0.0/0
798 70693 fw2modem all -- * eth1 0.0.0.0/0 0.0.0.0/0
0 0 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix
`Shorewall:OUTPUT:REJECT:''
0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0
Chain AllowICMPs (2 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 3 code 4
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 11
Chain AllowSMB (2 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT udp -- * * 0.0.0.0...
2005 May 25
9
Newbie going through a probably stupid thing
...0.0.0.0/0
> 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix `Shorewall:OUTPUT:REJECT:''
> 0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0
>
> Chain AllowICMPs (2 references)
> pkts bytes target prot opt in out source destination
> 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 3 code 4
> 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0....
2005 Dec 08
3
trouble with shorewall on Mandriva 2006 (2nd)
...n.comcast.net 2.6.12-12mdk #1 Fri Sep 9
18:15:22 CEST 2005 i686 AMD Duron(tm) unknown GNU/Linux
shorewall version output:
2.4.1
shorewall status:
Shorewall-2.4.1 Status at pcp08479598pcs.spedwy01.in.comcast.net - Thu Dec
8 06:04:45 EST 2005
Counters reset Wed Dec 7 08:10:49 EST 2005
Chain AllowICMPs (2 references)
pkts bytes target prot opt in out source
destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0
0.0.0.0/0 icmp type 3 code 4
0 0 ACCEPT icmp -- * * 0.0.0.0/0
0.0.0.0/0 icmp type 11
Chain Drop (1 references)
p...
2005 Jun 27
5
Bridging problem with Shorewall and OpenVpn
...ences)
pkts bytes target prot opt in out source
destination 0 0 ACCEPT udp -- * *
0.0.0.0/0 0.0.0.0/0 udp dpt:53
0 0 ACCEPT tcp -- * * 0.0.0.0/0
0.0.0.0/0 tcp dpt:53
Chain AllowICMPs (2 references)
pkts bytes target prot opt in out source
destination 0 0 ACCEPT icmp -- * *
0.0.0.0/0 0.0.0.0/0 icmp type 3 code 4
0 0 ACCEPT icmp -- * * 0.0.0.0/0
0.0.0.0/0 i...
2007 Dec 05
8
How does one use a module?
...</snip>
''allicmp-to-host'':
source => ''all'',
destination => ''$FW'',
order => 40020,
action => ''AllowICMPs/ACCEPT'';
''allow ssh'':
source => ''net'',
protocol => ''tcp'',
destinationport => ''22'',
order =>...
2005 May 29
17
Plans for 2.4.0
Hi folks,
Has anyone tested the changes to multiple ISPs/load balancing or
routestopped in 2.4.0-RC1 yet? We need to talk about what criteria we
will use for determining whether 2.4.0 is ready for release.
I''ve started configuring a firewall at work with the multiple ISPs
support, but its kernel doesn''t have connection marking support, so it''s
going to be a couple of
2005 Jun 14
1
Problem with samba broadcast
...* 0.0.0.0/0
0.0.0.0/0
7 1014 LOG all -- * * 0.0.0.0/0
0.0.0.0/0 LOG flags 0 level 6 prefix `Shorewall:OUTPUT:DROP:''
7 1014 DROP all -- * * 0.0.0.0/0
0.0.0.0/0
Chain AllowICMPs (2 references)
pkts bytes target prot opt in out source
destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0
0.0.0.0/0 icmp type 3 code 4
0 0 ACCEPT icmp -- * * 0.0.0.0/0
0.0.0.0/0...