Displaying 20 results from an estimated 20000 matches similar to: "Shorewall rpm failed dependency: iproute (ip is working)"
2005 Mar 23
9
multiple vpn connections out via shorewall
Hi All,
Just joined the list to try and solve a problem.
To show that I''ve read the rules I''ll start with the requested info
os linux kernel-2.4.27 with latest netfilter pom for gre and pptp conntrack
etc
iptables is 1.3.0 - downloaded and compiled with the pom stuff and the 2.4.27
kernel
shorewall version shorewall-2.2.1-2 from rpm
ip addr show
[root@squid3 root]# ip addr
2004 Dec 09
6
Can''t allow ICMP to firewall?
Hello,
I am stumped on a problem I am having with Shorewall 2.0.1 on Mandrake 10.
My setup is as follows. I have a /28 and have assiigned all ip addresses to
my firewall using aliases. I am able to setup rules to allow specific
traffic to specfic ip addresses on the firewall like so:
ACCEPT net:w.x.y.z $FW:w.x.y.z tcp 22
This works great for TCP and UDP traffic. I can
2004 Dec 16
9
Some help for a beginner please: terser logging
Dear newfound friends,
please be patient. For me reading and writing in English is more painful
than dissecting IP traces :)
I have tried reading through the FAQ but could not quite understand:
I would like the logs to be terser. I think I can live without MAC, LEN,
TOS, PREC, TTL, ID fields normally (maybe need them only in special
situations). Could not understand if/how I can achieve this.
2005 May 29
17
Plans for 2.4.0
Hi folks,
Has anyone tested the changes to multiple ISPs/load balancing or
routestopped in 2.4.0-RC1 yet? We need to talk about what criteria we
will use for determining whether 2.4.0 is ready for release.
I''ve started configuring a firewall at work with the multiple ISPs
support, but its kernel doesn''t have connection marking support, so it''s
going to be a couple of
2004 Dec 01
5
PPTP connections through Shorewall - WinXP Workstation to Win2003 Server
The problem scenario I describe was reported previously in the Shorewall
lists but its resolution does not seem to have made it into the lists.
Scenario:
Windows XP client seeking to establish a VPN connection to a Windows 2003
Server located behind a Shorewall firewall (running on Mandrake kernel 2.4.22-37mdk).
The connection cannot be made, the client reports error code 721.
Discussion:
2004 Oct 04
5
DNAT strange thing ???
Hi list,
This is my first post there.
CONTEXT :
--------------
I have a little lan behind a shorewalled box
(internet) -- NET_IP [gateway] LOC-IP -- (lan X.Y.0.0)
internet -> net zone connected to the gateway via a ppp interface
lan -> loc zone connected to the gateway via eth1
NET_IP and LOC_IP are defined in shorewall params file
GOAL :
---------
i want to forward http and
2003 Aug 31
4
linux-ha heartbeat .. failover firewall
I have searched your FAQ''s and read the documentation on your site as well
as googling. I am not able to figure this out. If you have any ideas can
you please help.
I am using the linux-ha failover with redundant firewalls.
As part of the function of the linux-ha software consists a service called
heartbeat which is a connection from each failover node through a serial
cable or ethernet.
2003 Feb 27
6
Shorewall 1.4.0 Beta 2
The second Beta is now available at:
http://www.shorewall.net/pub/shorewall/Beta
ftp://ftp.shorewall.net/pub/shorewall/Beta
Function from 1.3 that has been omitted from this version includes:
1) The ''check'' command is no longer supported.
2) The MERGE_HOSTS variable in shorewall.conf is no longer
supported. Shorewall 1.4 behavior is the same as 1.3 with
MERGE_HOSTS=Yes.
2005 Jan 30
20
FTP Transparent Proxy from Local To Net Through DMZ
Dear All,
Linux Kernel 2.4.20-8
Running Shorewall 2.2.0
ip addr show
1: lo: <LOOPBACK,UP> mtu 16436 qdisc noqueue
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 brd 127.255.255.255 scope host lo
2: eth0: <BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast qlen 100
link/ether 00:48:54:53:82:45 brd ff:ff:ff:ff:ff:ff
inet 62.68.254.178/28 brd
2004 Jun 30
1
[*] shorewall requirements - which command
Tom,
I''m setting up a new firewall using shorewall-2.0.3a. The box was
installed with the minimum, almost only the kernel.
before installing shorewall, I installed iptables 1.2.9 and iproute2. Then
I did a manual ./install.sh from the directory extracted from the tarball.
When I issued a shorewall start, I received hundreds of errors like:
/usr/share/shorewall/firewall: line 5520:
2004 Nov 11
5
URGENT!! some large websites cant be surfered
Clients: Some sites just show the top area not the full page. Some sites
cant be reached at all.
I think it 90% may be the MTU/MSS problem. But I already have set the
shorewall.conf CLAMPMSS=1400 or CLAMPMSS=Yes, but it doest make things
good.
I would be mad. Anybody helps me would so appreciated!
If you want know more info. to diag my problem, I would be please to.
2002 May 10
2
Help Improve the Shorewall Docs
At Tom Eastep''s request, an informal Shorewall Documentation Support =
Group (DSG) is hoping to relieve some of the writing and editing burdens =
that come with maintaining and improving the Shorewall documentation. =
The DSG welcomes and needs your suggestions and contributions about all =
aspects of the documentation, including structure, content, references, =
style, grammar --
2005 Jul 05
14
issues in tcrules
Hi! This is another thread of "setting gateway in interfaces file" and
while i dont want to create any confusion here, i have decided to open
a new thread.(which mean Diamond King no longer a subscriber to
shorewall-users)
Actually, i turned out not to be the MARK issues. Something is missing
and i got this error instead :-
Setting up Accounting...
Creating Interface Chains...
2004 Aug 06
9
how to define a dozens of interface as one zone
hi,
we use openvpn as for our vpn endpoints and we''ve got about 70-80 vpn
connections which means we have tun0 - tun80 interface. i''d like to
define one zone for all of our vpn connections how can I do that?
actualy our local zone is 192.168.0.0/17 (not 16) and all of the vpn''s
are in 192.168.128.0/17. our should i define somehow the local zone as
192.168.0.0/16? but in
2003 Mar 18
1
iproute and shorewall present but no install.
Hello, I have had a lot of success installing/configuring shorewall on my
own system using webmin. Recently, I have been contracted to do some remote
admin on a isp co-lo box all through a webmin server index connection from
my locally running webmin server connected to the remote server. I was able
to download shorewall from:
http://shorewall.infohiiway.com/pub/shorewall/LATEST.rpm but when
2004 Aug 03
4
Mandrake 10 - Shorewall 2.0.3a problem
Hi !,
I have this problem. On a Mandrake 10.0 server with all the updates (Kernel
2.6.3-15mdk, iptables-1.2.9-7mdk and shorewall-2.0.3a-1mdk), one of our
internal users have to FTP some files to our external web server. I think we
have the correct configuration and rules in shorewall, and have read the
http://www.shorewall.net/FTP.html document. Still, our users can''t FTP to
the
2005 Apr 14
5
Shorewall, PPTP VPN, and Samba
What I''m doing:
I have Shorewall on a SuSE 9.0 machine, which is the firewall/router
on the network. External interface is eth0 172.16.1.1, internal
interface is eth1 10.40.1.1. (I used the Two-interface Linux System
Quickstart Guide). All works well with that configuration. I also use
PPPD for dial-in clients, and have two modems for incoming calls.
Recently I added VPN interface
2005 Mar 09
13
Ways to get around DNS names in rules
I''m re-reading the section on dns names in the shorewall docs:
"I personally recommend strongly against using DNS names in
Shorewall configuration files. If you use DNS names and you
are called out of bed at 2:00AM because Shorewall won''t start
as a result of DNS problems then don''t say that you were not
forewarned."
Having been stung by this a few times
2004 Jan 26
6
Usersets
Is anyone using user sets? I''m considering dropping support for them in 2.0 in
favor of just listing individual user/groups in the rules file.
Thanks,
-Tom
--
Tom Eastep \ Nothing is foolproof to a sufficiently talented fool
Shoreline, \ http://shorewall.net
Washington USA \ teastep@shorewall.net
2003 Jan 08
14
prerouting newbie question/mistake :)
Hola and thanks for any help in advance
I installed mandrake 9 a few days ago and wanted to set up some
additional rules to shorewall, bu i failed :)
What i want to do is basicly route any incomming udp and tcp packets on
port 4665 to a workstation behind the router.
router with mandrake 9, eth0 (192.168.0.1) internal net, eth1(10.0.0.0)
connected to dsl modem and gets a dynamic ip