Displaying 20 results from an estimated 7000 matches similar to: "access deny host (ip) to access the Internet"
2004 May 26
13
Dropping established connections
Hello,
I have searched the list but couldn''t find the right answer. I want to
drop an established DNAT connection but could not manage it yet.
Someone earlier said to bring down the public interfaces, stop
shorewall, bring up the public interface and then start shorewall again
but this won''t work.
I also saw a message from Tom that someone then should unload all
iptables
2005 May 24
16
dhcp and shorewall
I want to run dhcp and shorewall on the same computer.It is
my gateway and that computer doing NAT for my network.How
can I set up shorewall to let only users that get theire
static ip address via dhcp, not to let users that had
static address.
2005 Mar 15
5
unable to filter or log vpn traffic
hi all,
i have a classic net topology with two local zone, a firewall/router
with dsl connection
loc1 (192.168.11.0/24)
----- fw ----- net
loc2 (192.168.12.0/24)
now on the local zone 1 (on a WinXP machine) i have installed
OpenVPN 2.x to make a test connection with a company.
OpenVPN is configured as client to use tun on udp
port 10000 with ip 10.0.0.2, on the other
2005 Apr 01
6
Shorewall and SuSE 9.3
The basic functionality of Shorewall 2.2.2 works fine with the
soon-to-be-released SuSE 9.3 (I have an early copy). I''ll be trying it
over the weekend with more complex configurations involving IPSEC and
OpenVPN.
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
PGP Public Key \
2005 May 24
6
RPM install issues
I am making a new box to test with and was trying to install shorewall
via rpm. So I download the shorewall 2.2.5 rpm and issue a rpm -ivh
shorewall-2.2.5-1.noarch.rpm. I then get an error:
error: Failed dependencies:
which is needed by shorewall-2.2.5-1.noarch
So as you can see there are no dependency issues. I thought I saw this
on the mailing list a while ago but I just searched for it I did
2003 Mar 20
11
Opinions Please
Although 1.4 is now released, there is one aspect of Shorewall''s design
that I''m still quite unhappy with. It involves two areas:
a) when and when not to create rules to allow inbound traffic on an
interface to be routed back out that same interface.
b) intrazone traffic.
I''m currently running 1.4.0 plus a change that:
a) Allows intrazone traffic unconditionally --
2003 Dec 07
2
Re: [Shorewall-newbies] Re: Shorewall-newbies Digest; Problems with blacklist and nat !
Hello,
I have forwarded this to the shorewall-users list.
You will find better support for this obscure problem there.
Regards,
Alex Martin
http://www.rettc.com
Cristian Valentin Barean wrote:
> Hello !
> My name is Barean Cristian, and I have a network of 35 users, on a
> Linux Mandrake 9.2 server.
> As I was adding more users in my network, I found a problem with
2004 Sep 02
2
Redirect to intranet webserver if not on maclist
First off, I want to say that everyone on this list is great. So heres
what I want to do..I have a maclist setup with all my users (roughly
400). There are constantly people leaving (deleting their accounts
which removes their MAC address) and registering for internet access ( I
have a php webserver that registers them, adds them to the maclist, and
allows them on the net). Is there a way to
2002 Dec 22
2
maclist option -> sorry good ver.
Setting up MAC Verification on eth0...
Error: Interface eth0 must be up before Shorewall can start
my :
/etc/shorewall/shorewall.conf:
MACLIST_DISPOSITION=REJECT
MACLIST_LOG_LEVEL=info
interfaces:
#ZONE INTERFACE BROADCAST OPTIONS
net ppp0 217.96.90.242 noping
loc eth0 255.255.255.0 routestopped,maclistmaclist:
maclist:
#INTERFACE MAC IP
2012 Jan 21
9
linux kernel 3.2.x gentoo maclist
how to make this work, its seem to me that netfilter is changed more or
less someplaces that shorewall do not support, using 4.4.27 shorewall
and shorewall6
suggestion welcomed
------------------------------------------------------------------------------
Try before you buy = See our experts in action!
The most comprehensive online learning library for Microsoft developers
is just $99.99!
2003 Dec 25
1
blacklist and not working dhcp
Return-Path: <viuwier@wp.pl>
X-Original-To: shorewall-announce@lists.shorewall.net
Delivered-To: shorewall-announce@lists.shorewall.net
Received: from smtp.wp.pl (smtp.wp.pl [212.77.101.160])
(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
(No client certificate requested)
by lists.shorewall.net (Postfix) with ESMTP id E3D8F33DB3
for
2005 Sep 29
20
maclist problem on a firewall/bridge/router system with masquerading
Hy,
sorry for my poor english
i think i''m having a very unusual problem and very dificult to track,
but i''ll try to explain it as best as i can.
here is my scenario:
a firewall/bridge composed of 3 ethernet devices and 1 virtual one.
my bridge (br0 ) is composed of eth0, eth1 and tap0
br0:eth0 is my connection to my router (200.244.92.1)
br0:eth1 is my connection to my
2003 Jan 08
3
Shorewall blacklist does all
Hello,
I''m a very happy user of shorewall but I have found a problem
or maybe a misconfiguration I made which I can not resolve.
I use a fairly large blacklist based on probes, nimda & codered
attacks, proxy & relay probes etc.
The only problem is that I want to block incoming trafic on
all ports FROM a block but it does also block a httpd, ping
etc TO a ip in a block what I do
2005 Mar 10
8
rules - access by mac address
Hi,
At the moment I am controlling my LAN client access to
the Inet by their MAC address. Currently I am putting
their MAC address in the rules file - now the number
of the PC that I want to manage is getting more and
more and it is not practicle to do this way anymore.
My question is, how can I have their MAC address in
other separate file?
Regards
http://www.debian.org/consultants/#Malaysia
2006 Apr 13
5
maclist or rule question
Hi,
I want to automate some of the maclist and rule functionality:
User connects to the network and gets a DHCP address from the shorewall box.
Using squid and redirection, all the user can do is go to a login page
on the firewall
User logs in correctly to the form on the webpage and a process captures
MAC and IP address info from the dhcpd.leases file
Once authenticated, a maclist entry and an
2005 Feb 08
15
Few questions
Hi,
I have a few problems with my shorewall configuration.
First of all, the option maclist seems no to be recognized.
I have this:
ghostwheel /etc/shorewall # cat interfaces | grep -v ''^#''
- eth1 detect dhcp,tcpflags,routefilter
loc eth0 detect tcpflags,maclist
When I look at shorewall-init.log, I found out:
2005 Mar 24
4
MAC address verification limitation
hi there. There are approx. 400-500 users in our
network and we plan to insert all their MAC addresses
into maclist and bind them together with IP address.
My question is whether shorewall is able to process
that much of MAC addresses without slowing the the
network speed performance? thanks for your time.
__________________________________
Do you Yahoo!?
Yahoo! Small Business - Try our new
2006 Jan 26
8
nat table remenbering nat''s
Dear All
Why NAT rules stays valid even if I flush nat anf table chains??
I have:
iptables -P FORWARD DROP
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -s SOME_IP -d SOME_BCP_5_IP --dport 1234 -j ACCEPT
iptables -i nat -A PREROUTING -s SOME_IP -d MY_INTERNET_IP \\
--dport 1234 -j DNAT --to-destination SOME_BCP_5_IP
The conection is
2004 Dec 15
3
[Fwd: 2 ftp serwers problem]
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
PGP Public Key \ https://lists.shorewall.net/teastep.pgp.key
2003 Mar 03
3
losing connection
Tom, or whomever reads this, when I say disconnect I mean close out IE6,
sorry for so unclear on this point. My IP address never changes unless I
unplug the modem. I have had the same IP address for ... well since I
had to reset it to hook it up to my Linux box.which was 2 weeks ago. If
I set DHCP on my eth1 interface that will contradict the static address
I have assigned to it,