Michael Badt
2003-Apr-28 09:18 UTC
[Shorewall-users] Help: Shorewall-what''s wrong with my configuration?
Hi, I have a stand alone (no LAN) PC with Mandrake 9.1. The PC is connected to a local printer (and the Internet) and thus runs CUPS. I assigned the PC (eth0) the following IP: 192.168.1.1. I installed and enabled shorewall (version 1.3.14) yet continue to get the following logs (once a minute): "Apr 25 12:20:22 Badt1 kernel: Shorewall:OUTPUT:REJECT:IN= OUT=eth0 SRC=192.168.1.1 DST=192.168.1.255 LEN=141 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=631 DPT=631 LEN=121". Looking at /etc/services I found that these messages (port 631) result from CUPS. In order to stop these bothering messages, I modified shorewall''s rules file as follows, yet these messages continue. Otherwise shorewall uses the default configuration (inc. policy). Please advise ! TIA ---------copy of rules (wo most of remarks------------------------------- #ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL # PORT PORT(S) #DEST ACCEPT fw loc:192.168.1.255 udp 631 #LAST LINE -- ADD YOUR ENTRIES BEFORE THIS ONE -- DO NOT REMOVE
Tom Eastep
2003-Apr-28 09:23 UTC
[Shorewall-users] Help: Shorewall-what''s wrong with my configuration?
On Mon, 28 Apr 2003 19:18:19 +0300, Michael Badt <michael-badt@barak- online.net> wrote:> Hi, > I have a stand alone (no LAN) PC with Mandrake 9.1. > The PC is connected to a local printer (and the Internet) and thus runs > CUPS. > I assigned the PC (eth0) the following IP: 192.168.1.1. > I installed and enabled shorewall (version 1.3.14) yet continue > to get the following logs (once a minute): > > "Apr 25 12:20:22 Badt1 kernel: Shorewall:OUTPUT:REJECT:IN= OUT=eth0 > SRC=192.168.1.1 DST=192.168.1.255 LEN=141 TOS=0x00 PREC=0x00 TTL=64 ID=0 > DF PROTO=UDP SPT=631 DPT=631 LEN=121". > >What do you have in the BROADCAST column for eth0 in /etc/shorewall/interfaces? -Tom -- Tom Eastep \ Shorewall - iptables made easy Shoreline, \ http://www.shorewall.net Washington USA \ teastep@shorewall.net