Displaying 20 results from an estimated 2000 matches similar to: "strange behaviour with rulesets"
2004 Nov 02
3
Shorewall 2.2.0 Beta 2
http://shorewall.net/pub/shorewall/2.2-Beta/shorewall-2.2.0-Beta2
ftp://shorewall.net/pub/shorewall/2.2-Beta/shorewall-2.2.0-Beta2
Problems Corrected:
1. The "shorewall check" command results in the (harmless) error
message:
/usr/share/shorewall/firewall: line 2753:
check_dupliate_zones: command not found
2. The
2005 Jun 24
8
The Shorewall list server is back on line
There was a lengthy power failure here in Shoreline this morning and my
firewall did not come back up when power was restored. The firewall is
now up and service to the server has been restored.
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
PGP Public Key \
2005 Apr 01
6
Shorewall and SuSE 9.3
The basic functionality of Shorewall 2.2.2 works fine with the
soon-to-be-released SuSE 9.3 (I have an early copy). I''ll be trying it
over the weekend with more complex configurations involving IPSEC and
OpenVPN.
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
PGP Public Key \
2005 Mar 10
7
norfc1918 not working in SW 2.2.1?
Hello all,
Yesterday I noticed that my system was "leaking" traffic towards the
10/8 network, I have shorewall installed on multiple machines ranging
from single interface devices to ones with 10+ interfaces. I tested all
the boxes and they are showing the same behavior.
All systems are CentOS 3.4, 2.4.21-27.0.2.ELsmp.
Shorewall version: 2.2.1
For the host mentioned is a single
2005 Jun 24
6
Is it that difficult?
Hello,
You will find in attachment the layout of my
current physical configuration.
For now, the Cable ISP is not used. Since it
is a dynamic ISP, my mailserver is rejected and
my domain name registers on blacklists like ORDB
and al.
I want it to be used as a default gateway except
for my mail server that would be seen as coming
from my "honest" ADSL ISP.
Here is
2005 May 29
4
webmin page
Hello,
I am not able to open the webmin web
interface on my server.
Shorewall is blocking it.
How to allow it on the server.
Thanks
Varun
2004 Sep 08
6
netfilter modules
hi,
there is no support for patch-o-matic netfilter modules. what i have to do
if i want to use several patch-o-matic modules?
which parts of code has to be changed and will that changed be included
into the main shorewall tree in future or not?
best regards
claus
2005 May 29
12
access deny host (ip) to access the Internet
I''m using shorewall 2.0.x at home as an Internet gateway for family.
However my brother always plays online games overnight, so my parents
asked whether I can do something on the gateway to control the time of
accessing the Internet.
I planned to put a script on crontab to schedule which it will execute
say at 12:00 night daily, the script will execute a command will deny
my brother
2004 Oct 26
3
problems on port forwarding
hi all,
my linux internet gateway has one fixed public ip and there are
several servers on the local net.
how to config shorewall such that it can forward a port on the
external int. to another port on to a server in local net. Simply
speaking,
external port http 8000 forward to internal port http 80
I used the DNAT to specify the source port as 8000 and dest port to 80
but it
2002 Sep 26
2
cross compiling
hi,
i want to build openssh in my uclibc environment with a cross-compiler. my
problem is that the configure-script is not very cross-compile friendly.
there are a lot of things that will be tested while configuring. if the
script find a cross compiler it exits with code 1. how to solve this issue
?
thanks
claus
2011 Aug 11
2
Samba Printing api_rpcTNP: \spoolss: SPOOLSS_OPENPRINTEREX failed
Hello,
after upgrading to samba 3.5.6 of Debian Squeeze some printouts will not printed. The same prinjob will printed after a couple of tries. I increased the loglevel and there are only a few messages which showing whtat could be the problem. The printjobs doesn't arrive at cups.
[2011/08/10 11:32:12.700665,? 0] lib/charcnv.c:650(convert_string_talloc)? Conversion error: Illegal multibyte
2003 Aug 31
4
linux-ha heartbeat .. failover firewall
I have searched your FAQ''s and read the documentation on your site as well
as googling. I am not able to figure this out. If you have any ideas can
you please help.
I am using the linux-ha failover with redundant firewalls.
As part of the function of the linux-ha software consists a service called
heartbeat which is a connection from each failover node through a serial
cable or ethernet.
2009 Jan 24
4
No logging with chain logdrop and logreject
Hello:
I just started using Shorewall this morning and must say that I''m very
impressed. Much nicer than what I was using previously.
I love the ability to type ''shorewall logdrop ww.xx.yy.zz'' and
completely block a particular IP address. However, the log part doesn''t
happen. When I look in the logdrop chain, there is no LOG prefix.
I''ve looked
2003 Mar 28
9
Squid
I''m attempting to setup Squid as shown on:
http://shorewall.sourceforge.net/Shorewall_Squid_Usage.html#DMZ
The firewall is a Bering 1.0 firewall running Shorewall 1.3.11, Red Hat
7.2 on the server in the DMZ. I''m not seeing the requests come in to the
server using tcpdump. The server is 192.168.2.1 connecting to eth2 on the
firewall, the local traffic I''m trying to
2005 Jun 27
2
RTNETLINK answers: File exists
Hi List,
I am new at this and trying to set up shorewall.
I was using mnf-en to do it but it was using an old version of shorewall
(shorewall-2.0.8-2mdk) and didn''t have the features I wanted. So I''ve
installed shorewall-2.4.0-1mdk.
Other bits of interest:
iproute2-2.6.10-1mdk
iptables-1.2.9-8mdk
I''m trying to get the providers feature working.
show capabilities:
2005 Mar 01
11
Can''t connect to Modem
Shorewall version 2.2.1
2 Interface setup.
eth1: 10.10.1.3
eth0: 192.168.1.2
modem is 192.168.1.1
I need to be able to connect to my adsl modem, but when shorewall is up I
get connection rejected.
I have added "192.168.1.1 RETURN" above the line "192.168.0.0/16 logdrop #
RFC 1918" in "/etc/shorewall/rfc1918" but still getting connection
rejected
Is there
2006 Jul 21
4
OpenVZ and virtuel network
Hello All
I installed shorewall 3.0.8 on Centos 4.3 with openvz.org kernel
it work well
i have in this Host 3 virtual servers (VPS)
i can access from a VPS to the internet , and with NAt rule (Via
Shorewall) i can access from Internet to the 3 VPS.
i want that all the 3 VPS can communicate between them.
i can''t do a tcp connection from a VPS to an other , in my shorewall log
in the
2011 Sep 14
3
Samba Printing api_rpcTNP: \spoolss: SPOOLSS_OPENPRINTEREX failed
Thats really annoying because the printing with samba is not possible, just printing directly to cups is possible. The clients are working with UTF-8, the server is working with UTF-8, don't know why character conversion should be a problem here.
More details:
[2011/09/14 13:55:24.173846, ?5] rpc_server/srv_pipe.c:2367(api_pipe_request)
? Requested \PIPE\\spoolss
[2011/09/14 13:55:24.173878,
2003 Nov 11
2
NEWBIE: DNAT Prob
Hi gang,
I''ve got a problem with shorewall, it keeps dropping packets when it
should be DNATing them.
I want all connections on a tcp port 4662 to be forwarded to a machine
on my network (192.168.0.5) - the port is used for mldonkey (P2P app).
It seems to be partially working - loads of packets are being DNAT''ed
but some are not - I cant figure out why!
The firewall
2003 Jan 03
6
RFC1918_LOG_LEVEL
I have tried (RH7.3/shorewall-1.3.12-1) both of the following in
shorewall.conf to eliminate ''rfc1918'' logging into /var/log/messages:
RFC1918_LOG_LEVEL=debug
RFC1918_LOG_LEVEL=notice
Neither appear to eliminate the logging.
Here''s what the ''logdrop'' chain shows:
1 229 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix \