Displaying 20 results from an estimated 60000 matches similar to: "Where Shorewall goes from here..."
2002 Nov 19
2
Shorewall operating status and how to stay "blocked"
Hi all,
I have just started using shorewall. So far so good. I have two
questions which I cant find an answer to either on the website or
googling.
They may be stupid so please forgive my ignorance.
1) What is shorewalls preferred operating status, running or stopped?
What I mean is, some firewalls start-up and run, and they do their
thing, then they stop. But the firewall is still really
2002 Apr 17
3
not quite a shorewall question but..
does anyone know how to enable the "udp loose" function in kernel 2.4.x? one
of my fave games requires this to work on the net and i''d really like to
move away from the 2.2 series kernels.
tia
2004 Dec 16
6
[OT] New (old) Firewall at shorewall.net
I''ve rebuilt my old P-II/233 with Debian Sarge and it is now serving as
my main firewall. It is running a home-built 2.6.9 kernel with the
ipsec-netfilter and policy match patches.
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
PGP Public Key \
2004 Feb 01
4
Shorewall 2.0.0 Alpha2
http://shorewall.net/pub/shorewall/Alpha/shorewall-2.0.0
ftp://shorewall.net/pub/shorewall/Alpha/shorewall-2.0.0
See if this change to proxy arp is more palatable.
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
2005 May 02
9
Sanity check for Shorewall and Openswan VPN and 2.6
I''m just looking for a quick sanity check to make sure what I''m finding
is really all necessary here.
I''m upgrading a gateway/firewall from Linux 2.4 to 2.6 using Mandrake 10.1.
In the old 2.4 kernel I structured my firewall rules around the ipsec0
interface, which I understand isn''t present with Openswan
running under 2.6 (no KLIPS). Ok,
So as I start to
2004 Oct 31
9
Maquerading through IPSECed wireless dropping packets selectively?
Hello,
I''m stuck IPSECing my wireless network at home and would appreciate any
comments. I appologize in advance if I''m wasting your time with trivia -
I''m not a professional and staring at the problem for days from various
angles hasn''t done me any good ...
My home server/firewall (morannon) is hooked up through an USB to
ethernet adapter (eth1) to my DSL
2005 Jan 07
6
Questions: place for doco, and routestopped during ''shorewall restart''
Hi folks,
A while back we had some discussions about integrating heartbeat and
shorewall. Thanks to your help and the excellent state of Linux
failover clustering, i''ve managed to install my high-availability
firewall. I know there''s already a howto for it at
http://www.xenos.net/library/hafirewall.html, but i thought i would
document my setup for others, since it''s
2002 Dec 05
7
New in CVS
The ''firewall'' script currently in the /Shorewall CVS project:
a) Is approximately 15% faster starting/restarting on my configuration --
please report your experiences with it.
b) Reloads Traffic Control/Shaping as part of "shorewall refresh"
c) Turns off the shell trace after an error has occured (except when the
command being traced is "stop" or
2004 Nov 05
8
Using Shorewall + Linux Virtual Server LVS/DR
I''m havign a HUGE amount of difficulty getting shoreline to work with LVS.
We use it here constantly so we know it works. The problem is packets come
in, get directed to a webserver, webserver returns the packet to firewall,
and then it goes into a black hole. rp_filter is off globally on all
interfaces. LVS seems to be working right....
I use shorewall tcrules to mark packets on
2007 Dec 14
6
kernel panic with shorewall
I have an old Pentium II which I use as a gateway and firewall
for a home network. The external interface is a modem on ppp and the
internal interface is ethernet. I have had this setup running
successfully for many years starting with the early 2.x series
Shorewall.
My ISP recently changed my dial-up ''phone number and presumably also
the system at the other end of my modem (they
2003 Jul 25
3
New Shorewall user trying to get ulogd setup
quick background:
RH9 (2.4.20-19.9)
Shorewall 1.4.6a-1
ulogd 1.00
Shorewall is working properly.
I''ve followed the FAQ instructions and everything appears to be setup
correctly. The problem is that I''m trying to get ulog going...but I''m
getting:
# service ulogd status
ulogd dead but subsys locked
I''m not sure if I was suppose to, but I also manually created
2005 Feb 23
13
Snort and Shorewall
Hello
I am looking for a way to have snort to dynamically update my shorewall config.
I have seen software out there but I would like to see if anyone had tried this
first.
Aslo I would like to know if there is a way clear the Netfilter tables when I do
a shorewall restart. The reason being is that when I make a change to my
firewall setting I want all connections to have to re-establish
2003 Dec 07
27
Re: Shorewall-devel Digest, Vol 11, Issue 4
Hiya,
> Ok with me -- if I get too frustrated with DocBook, I''ll just start
> editing the HTML again.
>
> -Tom
>
Well the fact that VIM is supported by Docbook is a plus .. But I still
think the Wiki idea is well .. Lets get the doc at a CVS and Docbook
stage .. Walking before running .. plz plz ..
Francesca
PS: I have thrown Windoze out the Window here (Pardon The
2002 Jan 19
6
pasv ftp
Hi,
ok Im all new to this :-)
for pasv ftp in your example you say for example to use ports
65500-65535, but i dont see that u open those ports in your example fw
scripts..?
any hints ?
--
Christophe Zwecker mail: doc@zwecker.de
Hamburg, Germany fon: +49 179 3994867
http://www.zwecker.de
"Who is General Failure ? And why is he reading my disk
2004 Oct 21
6
After shorewall restart NAT SMTP connection slow; reboot and it works fine
I recently implemented v2.0.9 using ''shorewall setup guide'' 2004-07-31.
Starting with block everything not known to be in use and opening ports
as complaints come in. This has led to a few rule changes. After a
rule change I use shorewall restart to reload the rules. Seems to work
OK... except for an outbound NAT SMTP connection from a mail server on
.122 to postini.com. The
2005 Jun 24
8
The Shorewall list server is back on line
There was a lengthy power failure here in Shoreline this morning and my
firewall did not come back up when power was restored. The firewall is
now up and service to the server has been restored.
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
PGP Public Key \
2004 Dec 02
8
Correct Shorewall version for RedHat ES3
Hello all --
I am trying to get Shorewall, ipsec and RedHat ES version 3 to cooperate.
Before posting any specific problems, I thought I''d find out if I have the
right stuff to work with. (I''ve gotten ipsec to work flawlessly with
Shorewall using RH 8 and 9 kernels, so I have some experience with it.
Shorewall 2.0.12 works fine on this ES 3 box, except for the ipsec part)
2005 May 05
4
Shorewall 2.3.0
http://shorewall.net/pub/shorewall/2.3/shorewall-2.3.0
ftp://shorewall.net/pub/shorewall/2.3/shorewall-2.3.0
WARNING: This is a development release and may be unstable
New Features in version 2.3.0
1) Shorewall 2.3.0 supports the ''cmd-owner'' option of the owner match
facility in Netfilter. Like all owner match options, ''cmd-owner'' may
only be applied to
2003 Jul 21
4
shorewall 1.4.6 question
why say:
Shorewall has detected the following iptables/netfilter capabilities:
NAT: Available
Packet Mangling: Available
Multi-port Match: Available
Connection Tracking Match: Not available
not available ? modules is loaded. or for rule = 0 ?
TC_ENABLE=Yes say Error: Traffic Control requires Mangle
2004 Feb 11
4
Shorewall, ipp2p and ipt_CONNTRACK
Hi!
Taking into consideration the great speed with which the use of P2P
filesharing systems is expanding, is there any plan of including ipp2p
and ipt_CONNTRACK support into shorewall? I''m sure that many admins
managing gateways would be very happy about it...
Thanx,
--
Mario R. Pizzolanti <mario@zavood.ee>
Zavood O?