Displaying 20 results from an estimated 1000 matches similar to: "Shorewall Rules and Configurations"
2009 Mar 04
1
MultiWAN & Vlans
Hello,
I''m trying to setup an 8 port wan configuration (pptp+pppoe) with one vlan trunk.
My internal networks are :
LAN(eth9): 10.0.0.0/16
VLAN10(eth9) 10.10.0.0/24
VLAN20(eth9) 10.20.0.0/24
VLAN30(eth9) 10.30.0.0/24
VLAN100(eth9) 10.100.0.0/24
I would like to post my configuration here since i don''t success to do the following:
1. Communicate between VLANxx to LAN
2009 Mar 13
0
Polices, Rules and Configurations - No Success (#/etc/shorewall/policy)
Hello,
I forgot to put my #/etc/shorewall/policy file:
# /etc/shorewall/policy
###############################################################################
#SOURCE DEST POLICY LOG LIMIT: CONNLIMIT:
# LEVEL BURST MASK
#
adm net DROP info
tlm net DROP info
#
net adm DROP
2010 Dec 12
3
weird fail with conversion to bridges?
I''m converting my network from a "one interface per segment" to a
"single connection with vlans", well, some hardware I have requires
using different vlan IDs. suffice it to say I need bridges to connect a
few different vlans that should all be one but can''t be because of
firmware constraints. so my first step is to get shorewall to know
about bridges.
2006 May 16
1
Traffic Routing/Shaping Problem
Hi,
I''m trying to use Shorewall (3.0.6) to accomplish what I thought was going
to be fairly simple. Unfortunately, I can''t get the dmz to work correctly,
and I''m getting martians logged against the interface at issue.
Any help I could get would be greatly appreciated!
A picture of my physical setup is attached. I have also attached a shorewall
dump.
To make a long
2005 Apr 19
5
1 to 1 nat of multiply pptp tunnels
Hi !
Recently i switched my internet provider, to get more speed but another
braindead setup regarding public ip addresses.
I now have 4 PPTP Tunnel available, of which i''m using one as the
gateway ip doing masquerading to other machines in my local lan,
excluding three other machines, which i would like to use 1:1 nat to
get them a direct access to one of the pptp tunnels.
I was
2011 May 24
1
L2TP ppp+ when using ppp0 for WAN
Hi, i connect to the internet over my eth4 interface using pppoe.
The internet always comes on ppp0.
I am trying to setup an L2TP/IPSEC VPN and i am reading http://www.shorewall.net/IPSEC-2.6.html#RW-L2TP
I notice in the example the interfaces file is given as:
#ZONE INTERFACE BROADCAST OPTIONS
net eth0 detect routefilter
loc eth1
2009 Feb 12
2
Getting ip_conntrack: table full, dropping packet on shorewall-lite
I have a bunch of servers, where I''ve deployed shorewall-lite. For us
is very useful to have a centralized repository of the firewall rules
deployed in our servers. One of this servers is pretty busy, handling
lots of connections. In that server I''m getting from time to time this
message: ip_conntrack: table full
If I where working in a custom made iptables firewall I will
2013 Apr 19
1
Can't connect to DSL modem on em1
Shorewall 4.5.15
3 Interface setup
em1
p3p1
p4p4
ppp0
Hi,
Since changing to NetworkManger on Fedora 18 I can no longer connect to the
DSL Modem, which is connected to Interface em1.
When the NetworkManger brings up the interfaces and ppp0, it no longer
assigns an IP to em1.
If I have ppp0 disabled and NetworkManger brings up the interfaces, em1
gets an IP of 192.168.1.2.
Then when I get
2005 Jun 30
2
"Blanks" in the interface file
Hi all!
I''m using shorewall 2.2.3 and I got a net device that seems to be a
point-to-point device (that''s what ifconfig suggests):
vpnlink Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:aaa.bbb.ccc.ddd P-t-P:aaa.bbb.ccc.ddd Mask:255.255.255.255
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1300 Metric:1
RX
2004 Dec 06
1
recomended internal(wired) "interfaces" options??
Hi:
According to http://www.shorewall.net/Documentation.htm#Interfaces
there is one recommendation for internal interface but wireless
Wireless Interface -- maclist,routefilter,tcpflags,detectnets,nosmurfs
a recommendation for wired internal interface?(100 win32 clients)
I use tcpflags,detectnets
thanks
2004 Jul 25
3
Openvpn, bridge and shorewall
Hi,
I have a Linux firewall based on shorewall with 2 NIC and ADSL (ppp0). My ppp0 ip is fixed. The internal NIC, eth1, is bridged with tap0, tap1 and tap2 to form br0. br0 subnet is 192.168.2.0/24.
The firewall is configured to masq internal traffic and block whatever needs to be blocked. It is also configured to tunnel openvpn v1.6.
I have a roaming laptop running XP. I can create a tunnel
2005 Apr 03
3
Problem with fresh two nic installation on FC3
Hi,
I''m having problems with new Shorewall installation on Fedora Core 3 (had
same problem with Core 2 and upgrade did not help even iptables was
upgraded from 1.2.9 to 1.2.11). I''ve followed two nic example, but
starting Shorewall drops all connections and don''t permit any outgoing
requests, even with "all allowed" policy. Policy file is below. Current
setup
2006 Apr 02
1
Two ISP
Hello all.
First of all, please be a bit indulgent to my poor English :-).
Second, this message is "kinda" BIG, so if you don''t like BIG
messages, simply don''t read it :-).
I''ve read http://shorewall.net/2.0/Shorewall_and_Routing.html
and http://shorewall.net/MultiISP.html, however I still a bit confused how
to organize what I need :-).
I''ve a
2004 Dec 30
9
shorewall shutting down eth0
Hello,
My server is on Mandrake 10.1 off.
eth0 is WAN with static IP connected 512 DSL
eth1 is LAN.
My default shorewall settings are :
Source zone Destination zone Policy Syslog level Traffic limit
loc net ACCEPT None None
fw net ACCEPT None None
net Any
2008 Mar 10
2
When starting shorewall its display rfc1981 error
Hello ,
The folllowing is the error problem:
Validating interfaces file...
ERROR: The ''norfc1918'' option may not be specified on an interface with an RFC 1918 address. Interface:eth2
The shorewall interface file:
net eth2 detect tcpflags,routefilter,norfc1918,nosmurfs,logmartians
P.S. I tried to remove norfc1918 from interface
2004 Feb 05
1
Norton personal firewall tells me that bad TCP packets are received
This is some of the messages I get:
TCP non-syn/non-ack packet on invalid connection. Packet has been dropped
TCP Source Port: http(80)
TCP Destination Port: 2595
TCP Message Flags: 0x00000019
The TCP message Flags varies. I''ve seen 0x00000011, 0x00000010,
0x00000018, 0x00000004, 0x00000014 and 0x00000019.
Intrusion: Invalid TCP Flags
TCP Source Port: 6881
TCP Destination Port: 4307
2006 Aug 23
5
OpenVPN and multiple ISPs
I have a server, server A, with three NICs: two to the Internet via
separate ADSL modems, and one to the LAN. The two ''net'' interfaces are
configured as described at http://www.shorewall.net/MultiISP.html. This
has been working for a number of months.
I am now testing an OpenVPN link between server A and another (currently
single-ISP) server (server B). I can establish the VPN
2013 Sep 10
6
lsm configuration issues...
Hi,
I use shorewall-4.5.4 + lsm-0.143 and it does not seem to work as expected...
When all providers are up, everything seems fine.
When one goes down, lsm says "link <provider> down event"... and it seems
ok but we then experience some problems such as a few unreachable sites,
DNS problems...
If I remove the downed provider from all confs and restart, everything works again.
2004 Nov 10
1
Problem with Shorewall/Routing VPN - LOC
Hello!
I configured a pptpserver on my firewall and followed the pptp-manual from
Shorewall.
Login via VPN to firewall (internal ip: 192.168.10.2) is ok and I can ping this
server via internal ip (and use it: add samba-shares, etc.).
Unfortunately I can''t connect to other hosts in my intranet (LOC).
Ping from vpn-client to clients in intranet fails, although Shorewall-Log shows
an
2005 Jun 11
0
Shorewall Configuration for Asterisk Box
Hi,
I've an Asterisk box acting as firewall with
Shorewall, yet I can't get a SIP client (Sipura 2000)
to connect remotely (behind a firewall). My Shorewall
Config as follows:
interfaces
#ZONE INTERFACE BROADCAST OPTIONS
net eth0 detect
dhcp,routefilter,norfc1918,tcpflags
loc eth1 detect tcpflags
zones
#ZONE DISPLAY COMMENTS
net Net Internet
loc Local Local