Tom Eastep
2002-Oct-08 13:32 UTC
[Fwd: Re[2]: [Shorewall-users] Yahoo Instant Messenger !]
More info on the post I cc''d this morning -- any ideas anyone? -Tom -------- Original Message -------- Subject: Re[2]: [Shorewall-users] Yahoo Instant Messenger ! Date: Tue, 8 Oct 2002 10:14:41 +0700 From: "Huy T.Q" <huytu@hcmc.netnam.vn> Reply-To: "Huy T.Q" <huytu@hcmc.netnam.vn> To: Tom Eastep <teastep@shorewall.net> References: <88152617772.20021007120139@hcmc.netnam.vn> <3DA19BD0.8050306@shorewall.net> thanks for Your answer, I add that rule but it is not efficient. Following is the result of traceroute like you tell me: traceroute: Warning: scsa.msg.yahoo.com has multiple addresses; using 216.136.22 7.166 traceroute to scs-foof.yahoo.com (216.136.227.166), 30 hops max, 38 byte packets 1 203.162.6.77 (203.162.6.77) 1.716 ms 2.202 ms 2.201 ms 2 203.162.143.201 (203.162.143.201) 284.695 ms 315.906 ms 242.701 ms 3 203.162.3.134 (203.162.3.134) 722.481 ms * 450.794 ms 4 207.176.97.105 (207.176.97.105) 530.524 ms 576.471 ms * 5 207.176.96.65 (207.176.96.65) 712.562 ms 613.689 ms 569.924 ms 6 i-2-0.paix04.hkt.net (202.84.249.26) 745.253 ms 723.523 ms 612.756 ms 7 i-11-0.paix-core01.PaloAlto.net.reach.com (202.84.251.21) 592.627 ms 698.9 32 ms 532.029 ms 8 134.159.63.22 (134.159.63.22) 343.865 ms 261.358 ms 340.306 ms 9 * ge-0-2-0.msr2.sc5.yahoo.com (216.115.100.237) 556.800 ms 453.736 ms 10 vl45.bas1-m.sc5.yahoo.com (66.163.160.226) 584.375 ms 421.759 ms vl41.bas1-m.sc5.yah oo.com (66.163.160.202) 609.386 ms 11 * * Hope you can help me, I don''t want leave Shorewall, I so like it! Thanks again, Huy Monday, October 7, 2002, 9:36:00 PM, you wrote: TE> Huy T.Q wrote: >> Dear Shorewall Users, >> I use Shorewall 1 year ago, and everything is so good (Thanks to Mr. >> Tom Eastep ). But now we have trouble with Yahoo Instant Messenger, >> we can not connect to Yahoo IM. And I check by ping from Firewall >> (Shorewall ) to scsa.msg.yahoo.com and all packets lost. >> In past time, I did not have this problem. Any idea ? TE> Be sure that you have a rule such as: TE> ACCEPT fw net udp 33435:33535 TE> then try a traceroute to scsa.msg.yahoo.com from your firewall. Since you TE> can''t ping to that site, there is likely a problem somewhere between your TE> firewall and there. TE> -Tom -- Best regards, Huy mailto:huytu@hcmc.netnam.vn -- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@shorewall.net