Andrew Judge
2002-Oct-18 14:05 UTC
[Shorewall-users] WAN setup over frame relay 7 locations
Hi - I have shorewall-1.3.8-1 on a RH 7.3 machine that acts as a firewall for my network. It was running the other day just fine, but today I have problems getting to the firewall. It is a frame-relay network with Cisco routers. Everything is 192.168.x.x / 24. I can''t ping the firewall from the WAN, but can from the main LAN. Sounds like a routing issue to me, but it was working for about a month or two. Like I stated, I can''t ping the Linux machine from the WAN, but the Linux machine can ping the other WAN workstations and routers just fine. Is there something that I should do on the Linux machine for the routes or in the Cisco routers or to the masq file? Any help much appreciated My firewall netstat -r is: Kernel IP routing table Destination Gateway Genmask Flags MSS Window irtt Iface 192.168.6.0 192.168.1.253 255.255.255.0 UG 40 0 0 eth1 192.168.5.0 192.168.1.253 255.255.255.0 UG 40 0 0 eth1 192.168.4.0 192.168.1.253 255.255.255.0 UG 40 0 0 eth1 192.168.3.0 192.168.1.253 255.255.255.0 UG 40 0 0 eth1 192.168.2.0 192.168.1.253 255.255.255.0 UG 40 0 0 eth1 192.168.1.0 * 255.255.255.0 U 40 0 0 eth1 207.87.80.0 * 255.255.255.0 U 40 0 0 eth0 127.0.0.0 * 255.0.0.0 U 40 0 0 lo default adsld1.cofs.net 0.0.0.0 UG 40 0 0 eth0 and my masq file is: eth0 192.168.1.0/24 eth0 192.168.2.0/24 eth0 192.168.3.0/24 eth0 192.168.4.0/24 eth0 192.168.5.0/24 eth0 192.168.6.0/24 Best regards, Andrew Judge
There isn''t enough detail here to give you any help. Please post a full description of you environment and what does/doesn''t work from where and hopefully the folks on the list will be able to help you. -Tom Andrew Judge wrote:> Hi - I have shorewall-1.3.8-1 on a RH 7.3 machine that acts as a firewall > for my network. It was running the other day just fine, but today I have > problems getting to the firewall. It is a frame-relay network with Cisco > routers. Everything is 192.168.x.x / 24. I can''t ping the firewall from > the WAN, but can from the main LAN. Sounds like a routing issue to me, but > it was working for about a month or two. > > Like I stated, I can''t ping the Linux machine from the WAN, but the Linux > machine can ping the other WAN workstations and routers just fine. Is there > something that I should do on the Linux machine for the routes or in the > Cisco routers or to the masq file? Any help much appreciated > > My firewall netstat -r is: > > Kernel IP routing table > Destination Gateway Genmask Flags MSS Window irtt > Iface > 192.168.6.0 192.168.1.253 255.255.255.0 UG 40 0 0 > eth1 > 192.168.5.0 192.168.1.253 255.255.255.0 UG 40 0 0 > eth1 > 192.168.4.0 192.168.1.253 255.255.255.0 UG 40 0 0 > eth1 > 192.168.3.0 192.168.1.253 255.255.255.0 UG 40 0 0 > eth1 > 192.168.2.0 192.168.1.253 255.255.255.0 UG 40 0 0 > eth1 > 192.168.1.0 * 255.255.255.0 U 40 0 0 > eth1 > 207.87.80.0 * 255.255.255.0 U 40 0 0 > eth0 > 127.0.0.0 * 255.0.0.0 U 40 0 0 lo > default adsld1.cofs.net 0.0.0.0 UG 40 0 0 > eth0 > > and my masq file is: > > eth0 192.168.1.0/24 > eth0 192.168.2.0/24 > eth0 192.168.3.0/24 > eth0 192.168.4.0/24 > eth0 192.168.5.0/24 > eth0 192.168.6.0/24 > > Best regards, > > Andrew Judge > > _______________________________________________ > Shorewall-users mailing list > Shorewall-users@shorewall.net > http://www.shorewall.net/mailman/listinfo/shorewall-users-- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@shorewall.net
Andrew Judge
2002-Oct-19 10:55 UTC
[Shorewall-users] WAN setup over frame relay 7 locations
Sure, here is a diagram and description http://www.aerobuilders.com/shorewall-dia.html If there is anyone out there that can give me some advice, it would be much appreciated. Andy -----Original Message----- From: shorewall-users-admin@shorewall.net [mailto:shorewall-users-admin@shorewall.net]On Behalf Of Tom Eastep Sent: Friday, October 18, 2002 10:25 AM To: Andrew Judge Cc: Shorewall-Users Subject: Re: [Shorewall-users] WAN setup over frame relay 7 locations There isn''t enough detail here to give you any help. Please post a full description of you environment and what does/doesn''t work from where and hopefully the folks on the list will be able to help you. -Tom Andrew Judge wrote:> Hi - I have shorewall-1.3.8-1 on a RH 7.3 machine that acts as a firewall > for my network. It was running the other day just fine, but today I have > problems getting to the firewall. It is a frame-relay network with Cisco > routers. Everything is 192.168.x.x / 24. I can''t ping the firewall from > the WAN, but can from the main LAN. Sounds like a routing issue to me,but> it was working for about a month or two. > > Like I stated, I can''t ping the Linux machine from the WAN, but the Linux > machine can ping the other WAN workstations and routers just fine. Isthere> something that I should do on the Linux machine for the routes or in the > Cisco routers or to the masq file? Any help much appreciated > > My firewall netstat -r is: > > Kernel IP routing table > Destination Gateway Genmask Flags MSS Window irtt > Iface > 192.168.6.0 192.168.1.253 255.255.255.0 UG 40 0 0 > eth1 > 192.168.5.0 192.168.1.253 255.255.255.0 UG 40 0 0 > eth1 > 192.168.4.0 192.168.1.253 255.255.255.0 UG 40 0 0 > eth1 > 192.168.3.0 192.168.1.253 255.255.255.0 UG 40 0 0 > eth1 > 192.168.2.0 192.168.1.253 255.255.255.0 UG 40 0 0 > eth1 > 192.168.1.0 * 255.255.255.0 U 40 0 0 > eth1 > 207.87.80.0 * 255.255.255.0 U 40 0 0 > eth0 > 127.0.0.0 * 255.0.0.0 U 40 0 0lo> default adsld1.cofs.net 0.0.0.0 UG 40 0 0 > eth0 > > and my masq file is: > > eth0 192.168.1.0/24 > eth0 192.168.2.0/24 > eth0 192.168.3.0/24 > eth0 192.168.4.0/24 > eth0 192.168.5.0/24 > eth0 192.168.6.0/24 > > Best regards, > > Andrew Judge > > _______________________________________________ > Shorewall-users mailing list > Shorewall-users@shorewall.net > http://www.shorewall.net/mailman/listinfo/shorewall-users-- Tom Eastep \ Shorewall - iptables made easy AIM: tmeastep \ http://www.shorewall.net ICQ: #60745924 \ teastep@shorewall.net _______________________________________________ Shorewall-users mailing list Shorewall-users@shorewall.net http://www.shorewall.net/mailman/listinfo/shorewall-users