fabiano stocco2
2011-Dec-22 19:36 UTC
Fwd: confirm 899689e155664d652518be9e5cdcd2f3caad64d9
---------- Mensagem encaminhada ---------- De: fabiano stocco2 <fabiano.stocco@agroparati.com.br> Data: 22 de dezembro de 2011 17:13 Assunto: Re: confirm 899689e155664d652518be9e5cdcd2f3caad64d9 Para: shorewall-users-request@lists.sourceforge.net Boa tarde Galera to com um problema aqui que é o seguinte. Tenho dois link de internet. O primeiro possui 2Mbit o outro tem 4Mbit, com isso estou montando um controle de download onde trata a entrada para a rede como base na origem dos links de WAN, isso para min controlar certinho a quantidade de dado trafegando por cada link. O problema que o shorewall não consegue fazer essa regra abaixo para min: #iptables -t mangle -A FORWARD -i eth1 -o eth3 -p tcp --sport 80 -j CLASSIFY --set-class 3:21 O Shorewall esta tratando a regra como tcpos e não como tcfor como esperado, com isso não funciona. Versão shorewall-4.4.23 Segue dados #tcdevices #NUMBER: IN-BANDWITH OUT-BANDWIDTH OPTIONS eth1 2mbit 2mbit eth2 4mbit 4mbit eth3 100mbit 100mbit classify #tcclass eth1 11 10*full/100 50*full/100 1 tos=0x68/0xfc,tos=0xb8/0xfc #Voip eth1 12 15*full/100 50*full/100 2 tcp-ack,tos-minimize-delay #Conexao eth1 13 45*full/100 full 3 #Dados eth1 14 30*full/100 50*full/100 4 default #Default eth2 11 5*full/100 50*full/100 1 tos=0x68/0xfc,tos=0xb8/0xfc #Voip eth2 12 15*full/100 50*full/100 2 tcp-ack,tos-minimize-delay #Conexao eth2 13 50*full/100 full 3 #Dados eth2 14 30*full/100 50*full/100 4 default #Default eth3:2 - 2mbit 2mbit 1 eth3:2:20 - 200kbit 400kbit 1 tos=0x68/0xfc,tos=0xb8/0xfc #Voip eth3:2:21 - 200kbit 400kbit 2 tcp-ack,tos-minimize-delay #Conexao eth3:2:22 - 1200kbit full 3 #Dados eth3:2:23 - 400kbit 400kbit 4 #Default eth3:3 - 4mbit 4mbit 1 eth3:3:30 - 200kbit 400kbit 1 tos=0x68/0xfc,tos=0xb8/0xfc #Voip eth3:3:31 - 500kbit 1mbit 2 tcp-ack,tos-minimize-delay #Conexao eth3:3:32 - 2mbit full 3 #Dados eth3:3:33 - 400kbit full 4 default #Default eth3:4 - 400kbit 400kbit 1 #Sem QOS #Tcrules ###################################################################################################################### #MARK SOURCE DEST PROTO DEST SOURCE USER TEST LENGTH TOS CONNBYTES HELPER # PORT(S) PORT(S) #############################UPLOAD WAN########################################## #Conexao 12 172.16.0.0/16 0.0.0.0/0 icmp echo-request,echo-reply 12 172.16.0.0/16 0.0.0.0/0 udp 53 12 172.16.0.0/16 0.0.0.0/0 tcp 53 #VOIP 11 $VOIP 0.0.0.0/0 tcp 4569,5060 11 $VOIP 0.0.0.0/0 udp 4569,5060 #Dados 13 172.16.0.0/16 0.0.0.0/0 tcp 1194,22017,60179,22,3389,631,5900:5904 13 172.16.0.0/16 0.0.0.0/0 udp 1194 ##############################DOWNLOAD LInk1########################################## ##Conexao 3:21 eth1 172.16.0.0/16 icmp echo-request,echo-reply 3:21 eth1 172.16.0.0/16 udp 53 3:21 eth1 eth3 tcp - 53,80 3:21 eth1 eth3 tcp 53,80 #VOIP 3:20 eth1 $SOUNDWAVE1 tcp 4569,5060 3:20 eth1 $SOUNDWAVE1 udp 4569,5060 #Dados 3:22 eth1 172.16.0.0/16 tcp 1194,22017,389,60179,22,3389,631,5900:5904,9102,9103 3:22 eth1 172.16.0.0/16 udp 1194,389,161 ##############################DOWNLOAD Link1########################################################### ##Conexao 3:31 eth2 172.16.0.0/16 icmp echo-request,echo-reply 3:31 eth2 172.16.0.0/16 udp 53 3:31 eth2 172.16.0.0/16 tcp 53 #VOIP 3:30 eth2 $VOIP tcp 4569,5060 3:30 eth2 $VOIP udp 4569,5060 ##Dados 3:32 eth2 172.16.0.0/16 tcp 1194,22017,389,60179,22,3389,631,5900:5904,9102,9103 3:32 eth2 172.16.0.0/16 udp 1194,389,161 #CONTINUE 0.0.0.0/0 0.0.0.0/0 all - - - !0 ##Sem QoS 3:4 $FW 172.16.0.0/16 tcp 22,9102,9103,3128,60179,389 Desde já obrigado Fabiano Stocco -- *Fabiano Stocco** **Sysadmin* Agro Industrial Parati Ltda - Averama 44-3672-8000 44-8444-6635** ------------------------------------------------------------------------------ Write once. Port to many. Get the SDK and tools to simplify cross-platform app development. Create new or port existing apps to sell to consumers worldwide. Explore the Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join http://p.sf.net/sfu/intel-appdev
fabiano stocco2
2011-Dec-22 19:36 UTC
Fwd: confirm 899689e155664d652518be9e5cdcd2f3caad64d9
---------- Forwarded message ---------- From: fabiano stocco2 <fabiano.stocco@agroparati.com.br> Date: 2011/12/22 Subject: Re: confirm 899689e155664d652518be9e5cdcd2f3caad64d9 To: shorewall-users-request@lists.sourceforge.net good afternoon Guys to have a problem here that is as follows. I have two internet link. The first has 2Mbit the other has 4Mbit , so I''m riding with a download control which handles input to the network based on the origin of the WAN links, this just right for min control the amount of data traveling on each link. The problem that shorewall can not make this rule below to min: # iptables-t mangle-A FORWARD-i eth1-o ETH3-p tcp - sport 80-j Classify - set-class 3:21 The Shorewall is trying to rule as tcpos and not tcfor as expected, does not work with it. Shorewall-4.4.23 Version The following data #tcdevices #NUMBER: IN-BANDWITH OUT-BANDWIDTH OPTIONS eth1 2mbit 2mbit eth2 4mbit 4mbit eth3 100mbit 100mbit classify #tcclass eth1 11 10*full/100 50*full/100 1 tos=0x68/0xfc,tos=0xb8/0xfc #Voip eth1 12 15*full/100 50*full/100 2 tcp-ack,tos-minimize-delay #Conexao eth1 13 45*full/100 full 3 #Dados eth1 14 30*full/100 50*full/100 4 default #Default eth2 11 5*full/100 50*full/100 1 tos=0x68/0xfc,tos=0xb8/0xfc #Voip eth2 12 15*full/100 50*full/100 2 tcp-ack,tos-minimize-delay #Conexao eth2 13 50*full/100 full 3 #Dados eth2 14 30*full/100 50*full/100 4 default #Default eth3:2 - 2mbit 2mbit 1 eth3:2:20 - 200kbit 400kbit 1 tos=0x68/0xfc,tos=0xb8/0xfc #Voip eth3:2:21 - 200kbit 400kbit 2 tcp-ack,tos-minimize-delay #Conexao eth3:2:22 - 1200kbit full 3 #Dados eth3:2:23 - 400kbit 400kbit 4 #Default eth3:3 - 4mbit 4mbit 1 eth3:3:30 - 200kbit 400kbit 1 tos=0x68/0xfc,tos=0xb8/0xfc #Voip eth3:3:31 - 500kbit 1mbit 2 tcp-ack,tos-minimize-delay #Conexao eth3:3:32 - 2mbit full 3 #Dados eth3:3:33 - 400kbit full 4 default #Default eth3:4 - 400kbit 400kbit 1 #Sem QOS #Tcrules ###################################################################################################################### #MARK SOURCE DEST PROTO DEST SOURCE USER TEST LENGTH TOS CONNBYTES HELPER # PORT(S) PORT(S) #############################UPLOAD WAN########################################## #Conexao 12 172.16.0.0/16 0.0.0.0/0 icmp echo-request,echo-reply 12 172.16.0.0/16 0.0.0.0/0 udp 53 12 172.16.0.0/16 0.0.0.0/0 tcp 53 #VOIP 11 $VOIP 0.0.0.0/0 tcp 4569,5060 11 $VOIP 0.0.0.0/0 udp 4569,5060 #Dados 13 172.16.0.0/16 0.0.0.0/0 tcp 1194,22017,60179,22,3389,631,5900:5904 13 172.16.0.0/16 0.0.0.0/0 udp 1194 ##############################DOWNLOAD LInk1########################################## ##Conexao 3:21 eth1 172.16.0.0/16 icmp echo-request,echo-reply 3:21 eth1 172.16.0.0/16 udp 53 3:21 eth1 eth3 tcp - 53,80 3:21 eth1 eth3 tcp 53,80 #VOIP 3:20 eth1 $VOIP tcp 4569,5060 3:20 eth1 $VOIP udp 4569,5060 #Dados 3:22 eth1 172.16.0.0/16 tcp 1194,22017,389,60179,22,3389,631,5900:5904,9102,9103 3:22 eth1 172.16.0.0/16 udp 1194,389,161 ##############################DOWNLOAD Link1########################################################### ##Conexao 3:31 eth2 172.16.0.0/16 icmp echo-request,echo-reply 3:31 eth2 172.16.0.0/16 udp 53 3:31 eth2 172.16.0.0/16 tcp 53 #VOIP 3:30 eth2 $VOIP tcp 4569,5060 3:30 eth2 $VOIP udp 4569,5060 ##Dados 3:32 eth2 172.16.0.0/16 tcp 1194,22017,389,60179,22,3389,631,5900:5904,9102,9103 3:32 eth2 172.16.0.0/16 udp 1194,389,161 ##Sem QoS 3:4 $FW 172.16.0.0/16 tcp 22,9102,9103,3128,60179,389 Fabiano Stocco -- *Fabiano Stocco** **Sysadmin* Agro Industrial Parati Ltda - Averama 44-3672-8000 44-8444-6635** ------------------------------------------------------------------------------ Write once. Port to many. Get the SDK and tools to simplify cross-platform app development. Create new or port existing apps to sell to consumers worldwide. Explore the Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join http://p.sf.net/sfu/intel-appdev
Tom Eastep
2011-Dec-22 21:04 UTC
Re: Fwd: confirm 899689e155664d652518be9e5cdcd2f3caad64d9
On Thu, 2011-12-22 at 17:36 -0200, fabiano stocco2 wrote:> > I have two internet link. The first has 2Mbit the other has 4Mbit , > so I''m riding with a download control which handles input to the > network based on the origin of the WAN links, this just right for min > control the amount of data traveling on each link. The problem that > shorewall can not make this rule below to min: > > # iptables-t mangle-A FORWARD-i eth1-o ETH3-p tcp - sport 80-j > Classify - set-class 3:21 > > The Shorewall is trying to rule as tcpos and not tcfor as expected, > does not work with it.Shorewall currently doesn''t allow CLASSIFY rules to be placed in the FORWARD chain. Sorry, -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________ ------------------------------------------------------------------------------ Write once. Port to many. Get the SDK and tools to simplify cross-platform app development. Create new or port existing apps to sell to consumers worldwide. Explore the Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join http://p.sf.net/sfu/intel-appdev
Tom Eastep
2011-Dec-22 23:20 UTC
Re: Fwd: confirm 899689e155664d652518be9e5cdcd2f3caad64d9
On 12/22/11 1:04 PM, Tom Eastep wrote:> On Thu, 2011-12-22 at 17:36 -0200, fabiano stocco2 wrote: > >> >> I have two internet link. The first has 2Mbit the other has 4Mbit , >> so I''m riding with a download control which handles input to the >> network based on the origin of the WAN links, this just right for min >> control the amount of data traveling on each link. The problem that >> shorewall can not make this rule below to min: >> >> # iptables-t mangle-A FORWARD-i eth1-o ETH3-p tcp - sport 80-j >> Classify - set-class 3:21 >> >> The Shorewall is trying to rule as tcpos and not tcfor as expected, >> does not work with it. > > Shorewall currently doesn''t allow CLASSIFY rules to be placed in the > FORWARD chain. >Here''s a patch. patch /usr/share/shorewall/Shorewall/Tc.pm < CLASSIFY1.patch To specify the FORWARD chain (tcfor), follow the classification with '':F''. Example: 3:21:F -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________ ------------------------------------------------------------------------------ Write once. Port to many. Get the SDK and tools to simplify cross-platform app development. Create new or port existing apps to sell to consumers worldwide. Explore the Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join http://p.sf.net/sfu/intel-appdev
Tom Eastep
2011-Dec-22 23:49 UTC
Re: Fwd: confirm 899689e155664d652518be9e5cdcd2f3caad64d9
On 12/22/11 3:20 PM, Tom Eastep wrote:> On 12/22/11 1:04 PM, Tom Eastep wrote: >> On Thu, 2011-12-22 at 17:36 -0200, fabiano stocco2 wrote: >> >>> >>> I have two internet link. The first has 2Mbit the other has 4Mbit , >>> so I''m riding with a download control which handles input to the >>> network based on the origin of the WAN links, this just right for min >>> control the amount of data traveling on each link. The problem that >>> shorewall can not make this rule below to min: >>> >>> # iptables-t mangle-A FORWARD-i eth1-o ETH3-p tcp - sport 80-j >>> Classify - set-class 3:21 >>> >>> The Shorewall is trying to rule as tcpos and not tcfor as expected, >>> does not work with it. >> >> Shorewall currently doesn''t allow CLASSIFY rules to be placed in the >> FORWARD chain. >> > > Here''s a patch. > > patch /usr/share/shorewall/Shorewall/Tc.pm < CLASSIFY1.patch > > To specify the FORWARD chain (tcfor), follow the classification with > '':F''. Example: 3:21:F >With the patch this time. -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________ ------------------------------------------------------------------------------ Write once. Port to many. Get the SDK and tools to simplify cross-platform app development. Create new or port existing apps to sell to consumers worldwide. Explore the Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join http://p.sf.net/sfu/intel-appdev
fabiano stocco2
2011-Dec-23 09:40 UTC
Re: Fwd: confirm 899689e155664d652518be9e5cdcd2f3caad64d9
Hi Almost worked, look at the messages after the patched and configured the tcrules. Thanks in advance Dec 23 07:36:10 galvatronvt1 admin: Shorewall restarted Dec 23 07:36:10 galvatronvt1 shorewall[19223]: done. Dec 23 07:36:29 galvatronvt1 shorewall[19740]: Compiling... Dec 23 07:36:29 galvatronvt1 shorewall[19740]: Processing /etc/shorewall/params ... Dec 23 07:36:29 galvatronvt1 shorewall[19740]: Processing /etc/shorewall/shorewall.conf... Dec 23 07:36:29 galvatronvt1 shorewall[19740]: Loading Modules... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Running /etc/shorewall/compile... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /etc/shorewall/zones... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /etc/shorewall/interfaces... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Determining Hosts in Zones... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Locating Action Files... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /usr/share/shorewall/action.Drop for chain Drop... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /usr/share/shorewall/action.Broadcast for chain Broadcast... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /usr/share/shorewall/action.Invalid for chain Invalid... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /usr/share/shorewall/action.NotSyn for chain NotSyn... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /usr/share/shorewall/action.Reject for chain Reject... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /etc/shorewall/policy... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Running /etc/shorewall/initdone... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Adding Anti-smurf Rules Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Adding rules for DHCP Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling TCP Flags filtering... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling Kernel Route Filtering... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling Martian Logging... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /etc/shorewall/tcdevices... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /etc/shorewall/tcclasses... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /etc/shorewall/providers... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /etc/shorewall/route_rules... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: Compiling /etc/shorewall/tcrules... Dec 23 07:36:30 galvatronvt1 shorewall[19740]: WARNING: Using an interface as the SOURCE in a T: rule requires the interface to be up and configured when Shorewall starts/restarts : /etc/shorewall/tcrules (line 35) Dec 23 07:36:30 galvatronvt1 shorewall[19740]: ERROR: Unknown Class (3:21:21)} : /etc/shorewall/tcrules (line 37) Dec 23 07:36:30 galvatronvt1 admin: ERROR:Shorewall restart failed 2011/12/22 Tom Eastep <teastep@shorewall.net>> On 12/22/11 3:20 PM, Tom Eastep wrote: > > On 12/22/11 1:04 PM, Tom Eastep wrote: > >> On Thu, 2011-12-22 at 17:36 -0200, fabiano stocco2 wrote: > >> > >>> > >>> I have two internet link. The first has 2Mbit the other has 4Mbit , > >>> so I''m riding with a download control which handles input to the > >>> network based on the origin of the WAN links, this just right for min > >>> control the amount of data traveling on each link. The problem that > >>> shorewall can not make this rule below to min: > >>> > >>> # iptables-t mangle-A FORWARD-i eth1-o ETH3-p tcp - sport 80-j > >>> Classify - set-class 3:21 > >>> > >>> The Shorewall is trying to rule as tcpos and not tcfor as expected, > >>> does not work with it. > >> > >> Shorewall currently doesn''t allow CLASSIFY rules to be placed in the > >> FORWARD chain. > >> > > > > Here''s a patch. > > > > patch /usr/share/shorewall/Shorewall/Tc.pm < CLASSIFY1.patch > > > > To specify the FORWARD chain (tcfor), follow the classification with > > '':F''. Example: 3:21:F > > > > With the patch this time. > > -Tom > -- > Tom Eastep \ When I die, I want to go like my Grandfather who > Shoreline, \ died peacefully in his sleep. Not screaming like > Washington, USA \ all of the passengers in his car > http://shorewall.net \________________________________________________ > > > ------------------------------------------------------------------------------ > Write once. Port to many. > Get the SDK and tools to simplify cross-platform app development. Create > new or port existing apps to sell to consumers worldwide. Explore the > Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join > http://p.sf.net/sfu/intel-appdev > _______________________________________________ > Shorewall-users mailing list > Shorewall-users@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/shorewall-users > >-- *Fabiano Stocco** **Sysadmin* Agro Industrial Parati Ltda - Averama 44-3672-8000 44-8444-6635** ------------------------------------------------------------------------------ Write once. Port to many. Get the SDK and tools to simplify cross-platform app development. Create new or port existing apps to sell to consumers worldwide. Explore the Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join http://p.sf.net/sfu/intel-appdev
Tom Eastep
2011-Dec-23 15:40 UTC
Re: Fwd: confirm 899689e155664d652518be9e5cdcd2f3caad64d9
On Fri, 2011-12-23 at 07:40 -0200, fabiano stocco2 wrote:> Hi Almost worked, look at the messages after the patched and > configured the tcrules.> Dec 23 07:36:30 galvatronvt1 shorewall[19740]: ERROR: Unknown Class > (3:21:21)} : /etc/shorewall/tcrules (line 37) > Dec 23 07:36:30 galvatronvt1 admin: ERROR:Shorewall restart failed >Please apply the attached patch on top of the first one. Thanks, -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________ ------------------------------------------------------------------------------ Write once. Port to many. Get the SDK and tools to simplify cross-platform app development. Create new or port existing apps to sell to consumers worldwide. Explore the Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join http://p.sf.net/sfu/intel-appdev
fabiano stocco2
2011-Dec-23 16:21 UTC
Re: Fwd: confirm 899689e155664d652518be9e5cdcd2f3caad64d9
Good Afternoon Thank you Tom Eastep gave the tests done just right here and it works 100%. Almost impede the shorewall because of this problem. Tom can tell me if the next version came out with this patch applied? Thank you again. Fabiano Stocco 2011/12/23 Tom Eastep <teastep@shorewall.net>> On Fri, 2011-12-23 at 07:40 -0200, fabiano stocco2 wrote: > > Hi Almost worked, look at the messages after the patched and > > configured the tcrules. > > > Dec 23 07:36:30 galvatronvt1 shorewall[19740]: ERROR: Unknown Class > > (3:21:21)} : /etc/shorewall/tcrules (line 37) > > Dec 23 07:36:30 galvatronvt1 admin: ERROR:Shorewall restart failed > > > > Please apply the attached patch on top of the first one. > > Thanks, > -Tom > -- > Tom Eastep \ When I die, I want to go like my Grandfather who > Shoreline, \ died peacefully in his sleep. Not screaming like > Washington, USA \ all of the passengers in his car > http://shorewall.net \________________________________________________ > > > > > ------------------------------------------------------------------------------ > Write once. Port to many. > Get the SDK and tools to simplify cross-platform app development. Create > new or port existing apps to sell to consumers worldwide. Explore the > Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join > http://p.sf.net/sfu/intel-appdev > _______________________________________________ > Shorewall-users mailing list > Shorewall-users@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/shorewall-users > >-- *Fabiano Stocco** **Sysadmin* Agro Industrial Parati Ltda - Averama 44-3672-8000 44-8444-6635** ------------------------------------------------------------------------------ Write once. Port to many. Get the SDK and tools to simplify cross-platform app development. Create new or port existing apps to sell to consumers worldwide. Explore the Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join http://p.sf.net/sfu/intel-appdev
Tom Eastep
2011-Dec-23 16:46 UTC
Re: Fwd: confirm 899689e155664d652518be9e5cdcd2f3caad64d9
On 12/23/11 8:21 AM, fabiano stocco2 wrote:> Good Afternoon > > Thank you Tom Eastep gave the tests done just right here and it works 100%. > > Almost impede the shorewall because of this problem. > > Tom can tell me if the next version came out with this patch applied? >Yes -- 4.4.27 will include this patch.> Thank you again.You are most welcome. -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________ ------------------------------------------------------------------------------ Write once. Port to many. Get the SDK and tools to simplify cross-platform app development. Create new or port existing apps to sell to consumers worldwide. Explore the Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join http://p.sf.net/sfu/intel-appdev