Displaying 20 results from an estimated 10000 matches similar to: "Shields-Up Scan of Shorewall Firewall"
2008 Jan 10
5
Want to log all ISP traffic to ULOG
I want to use fprobe-ulog (http://fprobe.sourceforge.net/) to generate
NetFlow information about traffic going through my router. The question
is how to get the logging rules added to the appropriate chains (I''m
assuming eth2_in and eth2_out in my case)? I''m using the perl version
of shorewall 4.0.6.
--
Orion Poplawski
Technical Manager 303-415-9701
2007 Dec 14
6
kernel panic with shorewall
I have an old Pentium II which I use as a gateway and firewall
for a home network. The external interface is a modem on ppp and the
internal interface is ethernet. I have had this setup running
successfully for many years starting with the early 2.x series
Shorewall.
My ISP recently changed my dial-up ''phone number and presumably also
the system at the other end of my modem (they
2008 Mar 26
8
Hub/Spoke OpenVPN can't communicate from Client A to Client B - FORWARD:REJECT:IN=tun0 OUT=tun0
Hi, I am running OpenVPN where i have one central hub VPN server, and multiple spoke VPN clients. I can ping from each client to the server and each client to computers on the subnet which the server resides (192.168.2.0/24) so it works ok there. I cannot however, ping from one client to another client. I guess the packet path would go:
clienta -> vpn -> shorewall/router -> vpn ->
2008 Mar 30
7
FTP DNAT not working - "Server sent passive reply with unroutable address"
Hi all!
I am a long time lurker, but have not posted until now.
My old trusted firewall machine broke a couple of weeks ago and I replaced it
with a XEN domU that is using DNAT and has two interfaces. The firewall domU and
the FTP server domU are both guests on the same dom0. All three machines are
running Debian/etch (stable) and Shorewall has version 3.2.6.
I can''t get FTP to work
2008 Jan 08
8
Shorewall and LVS-NAT (via fwmark) nat'd machines can't access the outside world directly
Hi guys,
I''m not sure where to post for help on this one, shorewall or lvs, I''ll
start with shorewall (only cause Tom is a gun at this stuff, and is polite
enough to tell me to bugger off to the LVS list if I''m posting in the wrong
one ;)
I have a single box that is my router/firewall/LVS.
Internet -- eth0 - router/firewall - eth1 --- internal lan
|
eth2
2007 Dec 14
2
Dual ISP
Attempting to setup a dual ISP on a gentoo box but I''m not sure how to
configure the routing in the /etc/conf.d/net configuration file. Does
shorewall do all the routing or do I set just the default route to the
PRIMARY outbound ISP?
Vernon
-------------------------------------------------------------------------
SF.Net email is sponsored by:
Check out the new SourceForge.net
2008 Jan 17
7
Netfilter, libpcap, ntop and promiscuous mode?
I have a really basic question (I think). We have two boxes connected
to a lan segment on a hub. One is a Windows box running "Show Traffic",
the other is a CentOS 5 Linux box running "ntop". Both boxes should be
able to sniff all of the traffic on that hub (not a switch).
The Windows box does just fine, Show Traffic is able to display traffic
destined for other boxes
2007 Dec 14
1
route_rules redirection not working
hi,
I am running shorewall 3.2.9 on Mandriva2007 with 2 ISPs. Certain
local IPs are directed to a specific ISP in route_rules, and this was
working perfectly. I had to reinstall Mandriva, and after that this
redirection is not working. My files are:
masq:
eth1 192.168.10.3 202.71.146.210
eth2 202.71.146.210 192.168.10.3
eth1 eth0 202.71.146.210
eth2 eth0 192.168.10.3
interfaces:
2008 Mar 28
1
Re: rfc1918
>> Only one remark. Information about 'init' file i found only in
>> releasenotes.txt for 4.1.6 (for setting up 'ifb' module) and i found
>> 'initdone' file in Shorewall config directory and without manfile also.
>> For me not very clearly as it use.
>
> http://www.shorewall.net/shorewall_extension_scripts.htm
On this page i found a
2008 Mar 31
2
IFB & ESFQ
Hello Tom,
Sorry, please but i again return to IFB question. If i correct
understand
in current situation IFB haven't profit from ESFQ in common cases (i mean
internal networks masquarading) so as we wait from ESFQ allocates bandwidth
fairly per source IP(internal) but IFB don't know internal IPs.
If i correct, what do you think what can help IFB to solve its main
disadvantage
2003 Jan 07
4
some ports not stealthed?
I''ve installed this fine software on my home network and am very pleased
with the ease of installation and especially the documentation.
My firewall box masq''s a private net via dialup modem. Configuration is
almost exactly as described in the two-interface example.
My question regards the result of a "internet test scan" that I found
via google search...when I run
2008 May 11
13
Message flooding of syslog
Greetings;
My syslog is getting 100s of thousands of messages like
the following (these are just a sample); (BTW I am
running Debian/lenny)
> May 11 12:41:31 gatekeeper kernel: BANDWIDTH_IN:IN=eth1 OUT=eth0 SRC=192.168.0.4 DST=64.15.118.171 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=37901 DF PROTO=TCP SPT=1307 DPT=80 WINDOW=17640 RES=0x00 ACK URGP=0
> May 11 12:41:31 gatekeeper kernel:
2008 Dec 05
6
xtables-addons+iptables-1.4.1+
Hi all,
We are trying to upgrade to iptables 1.4.1+
however the ipp2p module now it is included in the xtables-addons modules.
In the xtables-addons modules the commad line for ipp2p is changed
and the
-m ipp2p --ipp2p
option is not supported anymore ....
instead the maintainer requires that we use -m ipp2p --bit ... -m ipp2p
--kaza for each different P2P protocol.
as a result shorewall does
2008 Apr 04
1
GRE Tunnel problems
Hello,
I am doing some tests in my local network to test a GRE tunnel
configuration. I can established a tunnel but if I stop send packets
trough the tunnel , the tunnel goes down. I need to make ping from one
side of the tunnel to the another side to wake up the tunnel.
What could be my problem ?? Could be the VirtualBox ??
Thank you!
2007 Nov 22
4
Port 631 closed, not hidden
I have the firewall turned on my CentOS 5 box, but GRC is
reporting that 631 is closed instead of stealthed. If the
firewall isn't configured to allow that, then why might that
be happening?
Miark
2004 Sep 14
4
question about network setting for domain1
Hi,all,
I cannot get my network in domain1 work. Here is my configuration:
in dom0:
I have two network cards, the ip addrs are 141.213.10.110 and 192.168.0.4,
respectively. 141.213.10.110 is an external IP and can access internet
directly. The gateway should be 141.213.10.1.
/etc/xen/vfp: the domain1 configuration file, I created domain1 using ''xm
create vmid=1 -f
2007 Dec 10
8
Router A Unable to Connect to Router B on VPN
Hello all,
I''ve recently configured and IPsec VPN between my OpenSUSE 10.2 router
firewall running shorewall 3.4.4 and a friends Draytek Vigro 2930 ADSL
modem/router/firewall. All is good other than my router can''t ping
anything on my friends LAN, however machines on my LAN behind the
firewall can ping machines on my friends firewall without problem.
I''ve updated my
2008 Apr 26
2
Cannot use SSH from dmz to lan
Hello,
The shorewall version is shorewall-3.0.7-1 installed in Centos 5.1 (kernal 2.6.18-53.el5) on March.
Number one problem is:
I edited the policy file was
dmz loc ACCEPT info
I could use 3389 remote desktop to loc Windows 2003 server but couldn''t use SSH (22 port) to loc Linux server. Also I tried open that two ports in
2004 Sep 14
4
Memory oversubscription
Hi. First of all, thanks for Xen. It''s terrific!
I''m interested in doing memory oversubscription and am wondering if Xen
can do this (now or in the future).
For example, on a machine with 100MB available physical memory, can I:
1. Create a domain with a 90MB allocation
2. Inflate a balloon in that domain and return say 40MB back to Xen
I know there are mechanisms for doing
2008 Apr 09
2
Captive Portal with Shorewall
.
"Saluton",
Sorry by my poor english, I speak Portuguese.
I does a captive portal using:
- shorewall
- dhcpd
- thttpd (in port 8080)
- maradns
With Shorewall I use dinamic zones.
The initial zone in shorewall is
configured to redirects access to
internal thttpd port 8080, that
shows a login.cgi page.
With thttpd I rewrite original url.
The apache rewrite is very cool, but
thttpd