Displaying 20 results from an estimated 10000 matches similar to: "redirect: net to fw"
2005 Apr 01
4
Samba forwarding?
Hello,
I''m having a problem here with my setup which I could use some hints in
the right direction with.
I want to do the following :
- Windows boxes (Instrumentation, not my choice ...) are supposed to
samba into a linux fileserver (131.215.52.67)
- they don''t see the net directly, but are walled up behind a linux
firewall (172.16.0.1/131.215.35.26)
- both linux machines
2003 Oct 29
11
Shorewall prerouting to a manual proxy
Hallo,
I got a problem (I think it''s not a Problem, I am just to stupid to manage
it)
Iwant my Server (eth1: addr:10.0.123.1, Local Zone), eth0 is connectet to
the Student-Network (addr:172.16.129.106 Mask:255.255.248.0 gateway:
172.16.128.1, Net Zone), to forward all packages from port 80 on local
Zone to www-cache.uni-halle.de:3128 (172.16.128.1:3128) because I have to
use this
2006 Mar 09
3
Shaping questions
Hello Shorewall users,
I have some questions I am hoping someone can answer. I have searched
around the archives but so far I have been unable to find answers. I
am trying to configure traffic shaping on my router/firewall box
running Shorewall 3.0.5/kernel 2.4.31 and have run into some
problems/questions.
My basic set up is: 1500/256kbit ADSL (PPPoE/ppp0) -> Shorewall box
2002 May 14
3
[Shorewall-users] Redirect loc::80 to fw::3128 not work (fwd)
I''m beginning to believe that the use of the last column in the rules file
to designate redirection/forwarding is too subtle for many users. For 1.3,
I think I''ll do something like the following:
Current rule:
ACCEPT net loc:192.168.1.3 tcp 80 - all
New rule:
FORWARD net loc:192.168.1.3 tcp 80
Current rule:
ACCEPT net fw::3128 tcp 80 - all
New rule:
REDIRECT net
2003 Oct 22
2
help seeing DMZ from LOC
I have a three interface network (net,loc,dmz).
The internet interface (eth0) has a static IP.
Windows machine in the local network (eth1) use DHCP to get IPs from
the 192.168.10.0/24 netblock.
The Debian machine in the DMZ (eth2) gets a fixed IP through DHCP in
the 192.168.11.0/24 netblock.
The DHCP server is running on the firewall machine (not ideal, I know,
but that''s the way
2005 Feb 15
5
dnat problem
Hi, im running shorewall 2.0.16 with centos 3 (iptables v1.2.8), everything
is working fine for several days, i have configured a masq lan and all the
outgoing traffic is ok, but now i want to redirect (port forward) the
external web traffic to an internal machine, somethig like this
INTERNET ---------> SHOREWALL -------------------> INTERNAL_MACHINE
[public
2005 Jan 07
5
Shorewall, PPTP and Samba
Good Morning Everyone,
I have a server that runs Shorewall/Samba/PPTP (Poptop). When we try to
connect to the PPTP server from outside of the company, the Windows XP pro
client can establish the connection. We can then ping the server and the
clients behind the server without any problem, but the issue becomes that we
cannot map to any of the shares on the samba server or to any client for
that
2004 Jan 27
2
Shorewall help blacklist and restart/refresh
At the current time I am not subscribed to the mailing list.
I have a blacklist that I got from www.peerguardian.net that is rather
large ( 81 kb).
When shorewall start command is issued it takes about 20 mins for it to
load.
Is this normal or should I do this another way?
Also I noticed something very strange with shorewall ..
I have cron do a shorewall restart command every 24 hours and
2004 Oct 27
1
cannot establish connections from the machine to the internet
first thing: I''m not on the mailing list so please reply to
eyall@fitracks.com
now
i have a linux workstation inside the office''s LAN, from some reason i
cannot establish connections from the machine to the internet with those
settings.
i''ve been trying to change prefs and read almost all the docs but still
don''t know
what''s the problem so i have
2003 Feb 24
5
Bug in Shorewall check?
I made a boo boo in my config and put in this rule
#PPTP
DNAT net:213.67.241.162/217.209.46.204/32
loc:192.168.221.200 tcp 1723
DNAT net:213.67.241.162/32,217.209.46.204/32
loc:192.168.221.200 47 -
And the the following happened.. and I wonder why it didn''t complain? I
am sure I am just misunderstanding some doc
2005 Feb 07
2
blacklists and rules
Hi People, what files is processed first?, balcklist or rules, i want to
globally filter imesh, but at the same time allow managers to connect, i.e.
, imesh work on port 1214, i have this:
/etc/shorewall/blacklist
#ADDRESS/SUBNET PROTOCOL PORT
192.168.0.0/16 tcp 1214
192.168.0.0/16 udp 1214
2003 Oct 26
4
linux-xp x509 ipsec connection
hi,
I can''t get a freeswan 2.02 ipsec x509 connection at work
can somebody help me?
*************************************************************************************
global situation
*************************************************************************************
the linux gateway (chivas) is a single machine 192.168.1.250 with a local net 192.168.1.0/24,
a dyn IP via a DSL
2005 Apr 19
14
allow ssh access from net to fw?
Hi,
I''m trying to enable ssh (when that works, want to add:pop3s,smtp,web) from
the internet to the firewall but it does not work.
I managed to DNAT ftp to a host in the loc network (192.168.0.50) successful
but I don''t know why SSH:
Does not work for me:
ACCEPT net fw tcp 22
Works from the loc network:
ACCEPT loc fw tcp 22
I have tried also with (no success):
AllowSSH
2005 Dec 08
3
trouble with shorewall on Mandriva 2006 (2nd)
(Sorry, my previous post was sent in HTML format)
I am having a hell of a time with shorewall...
I have a Dlink DCM202 Cable modem with the Ethernet connected directly to
eth0 on the linux box. Then I have a second nic on the linux box connected
to a hub for
the internal network.
I am trying to allow traffic from the internet connect to my FTP and WEB
servers on my Winbloze box on the lan.
2005 Jan 11
2
All traffic is on the same adress
Hi
I have a trouble with my shorewall.
I have 5 Ips adresses on my internet interface.
I can ping any of these adresses, but the traffic take always the base adresse
on my interface. All the traffic is on the same adress, but I what to know
the traffric for each of these adresses.
I search a lot to find the setting for do that, I don''t know what is wrog in
my config, somebody can
2004 Sep 29
4
Re: start error]
thanks again for your sharp eye and speedy response. i have corrected the typos in the IP in the masq file. I am sorry to have to ask for more help but my pc''s on the local network can''t reach the dmz webserver using the webserver''s local or Public IP address. I need to be able to do this in order to test the split DNS setup for the network. Using ethereal on the
2004 Aug 03
4
Mandrake 10 - Shorewall 2.0.3a problem
Hi !,
I have this problem. On a Mandrake 10.0 server with all the updates (Kernel
2.6.3-15mdk, iptables-1.2.9-7mdk and shorewall-2.0.3a-1mdk), one of our
internal users have to FTP some files to our external web server. I think we
have the correct configuration and rules in shorewall, and have read the
http://www.shorewall.net/FTP.html document. Still, our users can''t FTP to
the
2003 Jan 16
3
Jan 16 17:49:33 murowall kernel: Shorewall:loc2net:CONTINUE:IN=eth0 OUT=eth2 SRC Shorewall:FORWARD:REJECT:IN=eth0 OUT=eth2
I have the problem when my localnetwork do telnet to the net
Shorewall:FORWARD:REJECT:IN=eth0 OUT=eth2
my files are the following:
policy
#SOURCE DEST POLICY LOG LEVEL LIMIT:BURST
loc net CONTINUE info
loc fw ACCEPT info
loc loc ACCEPT
loc dmz ACCEPT info
fw
2002 May 14
4
Redirect loc::80 to fw::3128 not work
The rule:
ACCEPT loc $FW::3128 tcp www
doesn''t work propertly, the http access does not redirect
to squid but directly exit.
what''s wrong?
Thanks
-------
Dario Lesca (d.lesca@ivrea.osra.it)
--------------------------------------
@@@@@@@ this is my shorewall-1.2.13 config:
#[/etc/shorewall/common.def]-----------------------------------------------
2004 Sep 22
3
Strange DNAT problems with shorewall 1.4.8
I''ve had some issues with my network, and I''ve had to reconfigure my
Gibraltar CD. It runs shorewall 1.4.8, and I have a 2-interface setup, so
I downloaded the relevant files from the install page.
Masq and such works, but I''m having a problem with my port forwarding. It
works for port 22, but it doesn''t seem to work for any other port.
I''ve turned