Alex Jouravlev wrote:> Sorry, I guess I haven''t looked passed "Otherwise".
>
> All the exact output in the attached file.
> Ping to the same address from firewall works perfectly
>
> A added a few unnecessary ACCEPTs to the 2-zone setup etc after I could not
get the ping through the first time
>
>
>
> /proc
>
> /proc/sys/net/ipv4/ip_forward = 0
You must be running Debian -- set IP_FORWARDING=Yes in shorewall.conf
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key