Displaying 20 results from an estimated 10000 matches similar to: "tcrules file and limit"
2004 Dec 18
14
Traffic Control
So after reading the traffic control documentation at shorewall.net I am
a little confused. I don''t understand how to use the tcrules file.
What I would ideally like to do is setup htb on a per user basis (either
by IP or MAC address). If anybody has any hints on the best way to do
this or is willing to explain the use of tcrules file a little better
(how I could mark it per IP or MAC)
2005 Jun 06
20
2 ISQs
Hello,
I tried to find the answer to my problem already but
it is a specialised one I think because nothing was
found.
I previously have a ISP who was very fast ("extreme
speed" service from Cable Modem) but that blocked
SMTP port and some other for poor non-commercial
users... And it gives dynamic addresses so no DNS
at home without tricks...
So I went to another
2005 Jan 26
11
Question on tcrules implementation
Hi all,
I moved wshaper 1.1 cbq file to tcstart, but none of my tcrules are being
observed. The only way I can set the marks is by editing the tcstart file.
Is there a way to incorporate for tcstart to read and apply my set marks in
tcrules?
Thank you,
~Andrew Nady.
2004 Sep 30
5
tcrules for proto "all" still not working in 2.0.9
I have just installed shorewall 2.0.9, having spent a day and a
half tracking down why my tcrules wasn''t working properly in 2.0.8.
I didn''t see the announcement of 2.0.9 because it didn''t go to -announce.
Anyway I have 2.0.9 now (the package from Debian incoming) and the problem
is still there.
My tcrules file says:
1 0.0.0.0/0 0.0.0.0/0 tcp 22
1 0.0.0.0/0 0.0.0.0/0
2005 Feb 18
7
$FW in tcrules
Hi Folks,
I''m a new user to Shorewall, it came installed on the redWall firewall
that I am using and I''m really happy with both projects! Thanks for all
your work on it!
I have a question about tcrules and $FW. I''m doing source policy
routing and need to be able to add an output rule to the mangle chain
with a source that is specific network, not 0.0.0.0/0. It
2004 Jan 20
6
[PATCH] Marking packets according to user in tcrules
Hi,
First of all, thanks to all shorewall developers. Shorewall is really
great.
Here is a patch to add the following feature :
This patch allows you to mark packets according to the user name under
which the program generating output is running.
To do so, the patch will allow you to write rules in the tcrules file
looking like that :
#MARK SOURCE DEST PROTO PORT(S) CLIENT USER
#
2005 Feb 27
10
tcrules question
Hi,
I am confused about the tcrules syntax. When I try to shape a web server
running on fw with this line:
4 fw 0.0.0.0/0 tcp - 80
it works
but the "80" must be in CLIENT PORT, my logic says it should be in the
"PORT" column (doesn''t work there)
am I missing something or are the columns labeled wrong?
thx
Jan
2012 Jun 17
2
tcrules' SIP HELPER is not helping
Hello
Asterisk sits in a Vserver guest (192.168.3.9) on the firewall. I can''t
seem to get the sip helper to mark the SIP packets though.
I have an ftp client on a different Vserver guest on the firewall. If
I put ftp in the HELPER column of tcrules I can mark those packets.
With sip in the HELPER column though nothing happens.
Attached is a "shorewall dump > dump.txt"
2003 Oct 15
4
tcrules ignored? wondershaper integration?
Hi,
first of all, let me thank you for your great Shoreline Firewall. I use
it with great success at home (protecting my WiFi connection).
And now if I could have a question about traffic shaping. I did read
everything I could find but I still have two problems: first, the MARK
from tcrules is not working in HTB based simple tc filter line ("handle
$MARK fw classid 1:20"). If I switch
2005 Jun 30
10
Long Shorewall Startup Times Revisited
Hello,
With reference to the problems listed below. I too am having
incredibly long start up times. I''m talking minutes here (around 5
minutes).
My configuration is not complex I don''t think. We are you using ldap
too and the settings are bellow. The network is up as I''m restarting
shorewall whilst the machine is running.
Any suggestions? Is there no way to
2005 Apr 21
6
bogons update
hi:
Just a litle update:
41/8 allocated to AfriNIC (APR 2005).
73/8 allocated to ARIN (MAR 2005).
hope it helps.
2005 Jun 29
5
Dual-ISP Masq
I know this is a FAQ and that it''s been discussed much before, I''m just
looking for a few key things.
I need to setup our gateway so that traffic FROM a range of IPs is sent
out, masqueraded, via a new cable connection.
I''m running 2.6.9.
Am I going to require any of the CONNMARK patches or other patches from
http://www.ssi.bg/~ja/#routes? I''m really not sure
2011 Jun 08
1
tcrules: src/dest ports and proto error
Hello,
It seems that the following restriction is not shown in the online man page
for tcrules:
ERROR: SOURCE/DEST PORT(S) not allowed with PROTO all :
/tmp/shorewall/tcrules (line 2)
Please let me know if this is expressed otherwise in the
documentation.
Thanks.
------------------------------------------------------------------------------
EditLive Enterprise is the world''s most
2005 Jul 02
6
Port redirection on standalone pc to pop3 proxy AV scanner
G''day all.
I''m trying to set up Clam AV scanning of incoming POP3 email to my
Thunderbird mail client; I have a standalone laptop with a 56k dialup
connection to my ISP.
I can''t seem to get port redirection working: I''m trying to redirect
incoming POP3 mail from my ISP''s mail server to p3scan which is
listening on 127.0.0.1:8110 and will do the AV
2005 Apr 01
6
Shorewall and SuSE 9.3
The basic functionality of Shorewall 2.2.2 works fine with the
soon-to-be-released SuSE 9.3 (I have an early copy). I''ll be trying it
over the weekend with more complex configurations involving IPSEC and
OpenVPN.
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
PGP Public Key \
2005 May 09
8
Shorewall protection?
Hy shorewall users :))
I have the following config in my shorewall:
DNAT net:200.137.193.2 loc:192.168.0.55 udp
135,445 - 200.137.193.38
DNAT net:200.137.193.2 loc:192.168.0.55 udp
137:139 - 200.137.193.38
DNAT net:200.137.193.2 loc:192.168.0.55 tcp
135,139,445 - 200.137.193.38
The IP
2005 May 24
6
RPM install issues
I am making a new box to test with and was trying to install shorewall
via rpm. So I download the shorewall 2.2.5 rpm and issue a rpm -ivh
shorewall-2.2.5-1.noarch.rpm. I then get an error:
error: Failed dependencies:
which is needed by shorewall-2.2.5-1.noarch
So as you can see there are no dependency issues. I thought I saw this
on the mailing list a while ago but I just searched for it I did
2005 Mar 16
3
mark range
(excuse me for my english)
why mark range in tcrules is 1-255 ?
iptables support marks > 255.
Leandro.
2005 Feb 02
6
Need help with Shorewall
I am using debian sarge. I want to block all incoming requests except
DNS (port 53) and allow all outgoing traffic. I did a apt-get
shorewall. When I start shorewall, I cannot even ping to any external
site. I am a newbie and difficult to follow the online guide. Can
anyone please help me.
Thanks !
2010 May 26
1
shorewall-tcrules.xml
Don''t know whether you''re interested in errors this trivial. Diff file
attached.
Regards
Fog_Watch.
------------------------------------------------------------------------------