Displaying 20 results from an estimated 8000 matches similar to: "nat problem"
2004 Sep 29
10
DNAT + Masq Problem - Yes I read the FAQ I promise
I have a debian woody machine acting as a firewall for a small
network. I am trying to do a simple DNAT to port 80 on the protected
webserver and masquerade all traffic from the protect subnet outbound.
After having read the FAQ and various posts regarding problems with
DNAT I''m afraid I''m no closer to a solution. Based on the output from
"shorewall show nat" I
2004 Dec 02
11
another network to add
Hi Tom (and others)
encase you don''t know my network already ;) here''s a quick run down
eth0 lan 192.168.1.1/255.255.255.0
eth1 wan1 172.30.7.4/255.255.240.0
eth2 wan2 202.37.230.93/255.255.255.192
eth3 wan3 203.96.213.73/255.255.254.0
I''ve got routes and rules for all the above interfaces :)
I want to add another one, however I fear this might cause some issues
I have
2004 Oct 14
16
Squid as a transparent proxy
Hi,
I followed the instructions in the section "Squid
(transparent) Running on the Firewall" on
http://www.shorewall.net/Shorewall_Squid_Usage.html to
setup Squid transparently on a Linux gateway. My net
is as follows:
loc subnet --- fw Linux Gateway --- ADSL router
192.168.1.0/24 192.168.1.92 (eth1) WAN.WAN.WAN.2
(gw = WAN.WAN.WAN.WAN (eth0)
192.168.1.92) (gw =
2005 Jun 06
23
Multi-ISP in 2.4.0
Hello Shorewall list,
I''m a happy Shorewall user since a few years now and everything works fine
for me except one thing that I try to implement since a week, the multi-isp.
I''ve downloaded the 2.4.0 Stable release yesterday and tried the RC2 since a
week.
My config is a Debian running a kernel 2.4.27 home made with the
CONNMARK.diff patch applied
I''m using 2 ISP,
2004 Nov 19
14
FAQ 32
What changes would I need to make if there is a 4th interface that is going
to a DMZ
Thanks
Gene
2004 Aug 20
11
Cannot ping an address on the internet !
I have allowed ALL of the local users to ping the internet but they
currently get the following error and cannot access the internet !
I know it is something I have done wrong (I think it is a routing problem
but just cannot find out what)
The error is:-
Reply from 212.219.13.74: destination host unreachable.
My eth1 is 10.0.0.1 and the users can ping that OK
My eth0 is 212.219.13.74 (connected
2005 Jan 30
20
FTP Transparent Proxy from Local To Net Through DMZ
Dear All,
Linux Kernel 2.4.20-8
Running Shorewall 2.2.0
ip addr show
1: lo: <LOOPBACK,UP> mtu 16436 qdisc noqueue
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 brd 127.255.255.255 scope host lo
2: eth0: <BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast qlen 100
link/ether 00:48:54:53:82:45 brd ff:ff:ff:ff:ff:ff
inet 62.68.254.178/28 brd
2002 Nov 20
8
Proxy ARP
Hi all!
I posted earlier about the proxy arp configuration =
http://shorewall.sourceforge.net/shorewall_setup_guide.htm#NonRouted, =
and was probably not sufficiently knowledgeable on the subject. I''ve =
gone through a bunch of documents on proxy arp, subnetting with proxy =
arp and the documentation at shorewall, and have come up with a setup =
that would be perfect for the job at hand
2005 Jul 04
4
setting gateway in interfaces file
I tried to the new GATEWAY option in
/etc/shorewal/interfaces file but it didnt work. My
network setting consists of 2 ISPs line and i would
like to have eth0 to connect to for example,
192.168.15.254 while eth1 connected to 192.168.33.254.
I restarted shorewall and nothing is wrong. However,
the traffic still goes to the default gateway as shown
in "route -n" command. For example, i
2005 Mar 02
12
Problem with outgoing Masquerade
I''m having another little problem with my new firewall. I want outgoing port
25 from my mail server to appear on the address 65.223.121.227 so I created
the file masq:
eth2 192.168.124.18 65.223.121.227 tcp 25
eth1 eth5
eth1 eth3
eth1 eth4
eth1 == net0 == 209.189.103.196/27
eth2 == net1 == 65.223.121.237/28
eth3 == dmz0
eth4 == dmz1
eth5 == loc ==
2006 Jan 17
12
Multiple ISPs: How to force $FW traffic to a specific ISP (reprise)
Hi!
I have reprise try to resolve this problem, suspended from 17 dec 2005
I have try to apply the suggest of Jerry (see above).
The problem still exist.
See attach shorewall config, dump and tcpdump when I check to exit whit
SSH from firewall...
In the masq file is reported the last my attempt in order to resolve my
problem, however I have test also the example reported in MultiISP.html,
but
2005 Jun 28
1
Nat as internal firewall
I have a strange situation. I have a shorewall firewall with 4
interfaces. This firewall is an internal lab firewall with all 4
networks being private. The configuration is as follows:
Eth0: 192.168.10.187 - This is the main lab network
Eth1: 10.10.10.1
Eth2: 172.26.4.1
Eth3: 192.168.1.1
I would like to be able to put a host behind this firewall with
interfaces on all 3
2006 Mar 25
2
Multiple uplink problems
I''ve installed Shorewall 3.0.5 on a Debian Sarge box, and I''m
attempting to route internet traffic through a couple of ISPs, and I''ve
come up against some problems.
The first is that one of my links is a pppoe connection to a wireless
modem, and I can''t configure it to have a static IP address...
therefore I can''t see how I can set up the two
2003 Jul 09
2
router in a subnet again :)
Hi,
after migrating to shorewall firewall from my own iptables rule set (to
utilise freeswan vpn tunnels) I have successfully configured a 3 interface
firewall with net2net vpn tunnels, with the help of the shorewall
documentation. However I cannot seem to configure my final step which is to
masq another subnet attached to my LAN (LANB, via Cisco 1603 router) to get
internet access via the
2005 Feb 12
5
Wireless - routing or bridging - Part Deux
I have added a 4th NIC to my setup, and want to set up wireless. I have
stared at the configuration Tom has for the last week, and my eyes are
crossing.
eth0 "net" goes to my internet connected firewall with a 192.168 address
eth1 "loc" goes to my switch connected to local switch also 192.168.x
eth2 "work" goes to my office with a 172. address
eth3 Trying to
2005 Jul 05
14
issues in tcrules
Hi! This is another thread of "setting gateway in interfaces file" and
while i dont want to create any confusion here, i have decided to open
a new thread.(which mean Diamond King no longer a subscriber to
shorewall-users)
Actually, i turned out not to be the MARK issues. Something is missing
and i got this error instead :-
Setting up Accounting...
Creating Interface Chains...
2004 Dec 06
1
MASQ
Is it possible to somehow build this rule, where net could be any IP on
the net?
/etc/shorewall/masq
#INTERFACE SUBNET ADDRESS PROTO PORT(S)
eth3:10.10.10.7 net 10.10.10.1
Thanks, David
2010 Mar 17
2
DNAT Problem
Hi everyone!
I''m having time out problems when using a DNAT rule.
Rule:
DNAT:info cmtc loc:192.168.0.158 tcp 8011
Log:
Mar 17 17:50:17 gw kernel: [1583997.524924]
Shorewall:cmtc_dnat:DNAT:IN=eth3 OUT= SRC=10.1.0.2 DST=10.0.0.2 LEN=60
TOS=0x10 PREC=0x00 TTL=62 ID=4279 DF PROTO=TCP SPT=32791 DPT=8011
WINDOW=5840 RES=0x00 SYN URGP=0
Telnet:
root@emudar:~# telnet
2004 Dec 03
1
Re: Shorewall-users Digest, Vol 25, Issue 9
> Message: 2
> Date: Fri, 03 Dec 2004 10:10:35 +1300
> From: Paul <lists@loudas.com>
> Subject: [Shorewall-users] another network to add
> To: Shorewall List <shorewall-users@lists.shorewall.net>
> Message-ID: <41AF84CB.5080304@loudas.com>
> Content-Type: text/plain; charset=ISO-8859-1; format=flowed
>
> Hi Tom (and others)
> encase you
2006 Mar 24
10
Multi-ISP with one Dynamic IP
I have two feeds, one with a static IP and one with a dynamic IP. How
can I configure a Multi-ISP setup with the dynamic IP, or can I? I don''t
think the gateway will change, just the interface IP.
--
Chris Mason
NetConcepts
(264) 497-5670 Fax: (264) 497-8463
Int: (305) 704-7249 Fax: (815)301-9759 UK 44.207.183.0271
Cell: 264-235-5670
Yahoo IM: netconcepts_anguilla@yahoo.com
--