Displaying 20 results from an estimated 9000 matches similar to: "Another Inquiry"
2004 Oct 11
5
Intermittant Samba glitch
Hi there,
Let me just start by saying that I am a bit of a Linux newbie, but that Shorewall seems an excellant product. The issue I''m reporting wont stop me from using it, it still does 99% of what I need.
Anyway, I have a resonably simple two interface system. My server (HatMannz, P3-900MHz with a RAID-1 array of 80GB IDE drives running Red Hat 9.0) connects to a cable modem via eth1
2004 Dec 25
5
Thick head still having problems with subnets (?)
I have defined a Home zone and placed it before the Net zone. Defined a
host 192.168.174.242 as a trusted host. Now if I ping from 242 to my fw
it works just fine (also tweaked the norfc1918 file).
Thing I do not understand is why if I try pinging or FTPing from FW to
242 I hit the all2all reject rule !
I tried reading the rules and from the INPUT chain I see a eth0_in chain
which in turn
2004 Oct 05
6
Something Changed?
Problem:
"Firewall" machine cannot get DNS but is allowing DNS through internally.
Something changed with the configuration but we''re not sure what. Here is
the pertinent info:
Shorewall Status Entries
Oct 5 09:24:50 all2all:REJECT:IN= OUT=eth2 SRC=192.168.7.55
DST=65.175.131.201 LEN=55 TOS=0x00 PREC=0x00 TTL=64 ID=50982 DF PROTO=UDP
SPT=32973 DPT=53 LEN=35
Oct 5
2002 Oct 12
2
logs analise
My logs show thats:
A internal client search my proxy
(192.168.0.3)
Oct 12 12:40:33 massayo kernel:
Shorewall:all2all:REJECT:IN=3Deth1 OUT=3D
MAC=3D00:e0:7d:82:0f:fe:00:04:75:99:28:63:08:00
SRC=3D192.168.0.215 DST=3D192.168.0.3
LEN=3D63 TOS=3D0x00 PREC=3D0x00 TTL=3D128
ID=3D25902 PROTO=3DUDP SPT=3D3028 DPT=3D53 LEN=3D43
Why OUT is empty?
From: Server (DMZ)
Oct 12 12:40:34 massayo kernel:
2005 Jan 11
2
dnat problem
Hi,
I have a proxy/firewall,
I want to dnat requests for 193.205.140.106 on port 443 towards
10.2.15.23 and requests for 193.205.140.106 on ports 4330 and 3389
towards 10.2.15.25, these rules must apply from internet, loc and fw
(some client use a proxy on fw to reach these servers)
I have tried with the following rules:
DNAT net dmz:10.2.15.23 tcp 443 -
2006 Feb 12
11
Local Network Can't Get Past Shorewall to the Internet
Greetings all,
I have just install Shorewall on a Debian system and
I''m using it as a firewall on an internal network.
The specifics of the system are as follows:
firewall:/var/log# shorewall version
3.0.4
firewall:/var/log# uname -a
Linux firewall 2.6.12-1-386 #1 Tue Sep 27 12:41:08 JST
2005 i586 GNU/Linux
Shorewall start successfully and $FW can connect to
the Internet for upgrading
2005 Jun 11
7
help connection is dropping every 10min
Hi,
I have some problems with shorewall,
I got disconnected every 10 minutes..
All the connections stops
I am using Shorewall version 2.4.0-RC2
and it is running on debian 3.1r0
I can''t seem to find the problem.
I hope you can help me with this. i post my log so that you can maby
see where the problem is.(i have filtert some ip addresses)
/sbin/shorewall show log
Shorewall-2.4.0-RC2
2003 Jan 03
1
Shorewall problems
I have installed Shorewall OK and it seemed to be
working OK however I am having a problem with
rejecting local request to the net in my test
environment.
The problem is when I put in the policy file the line
loc net REJECT info
the PC on the local network can still ping the PC that
I am using to simulate the internet. Also there is no
log entry that the request has been rejected. I have
also
2004 Dec 29
18
No response on port 80 with Shorewall
I have problem getting answer on http request from all my local subnets
but not from local subnet.
Ping and requests on ports 21 22 23 25 110 works fine.
I logged port 80 in rules files and I got
accept entry same for local subnet and other subnets.
Local subnet is 192.168.6
Dec 29 09:52:40 zinfsrv2 kernel: Shorewall:loc2fw:ACCEPT:IN=eth0 OUT=
MAC=00:09:6b:07:ca:cc:00:10:b5:fa:bd:71:08:00
2003 Aug 31
1
sane network scanning problem
Hallo,
i have a problem to configure shorewall to enable scanning over the
network with sane.
The scanner is located at the firewall hosts local interface.
Why do i get a "all2all" message and not "loc2loc"
Aug 25 14:55:26 router saned[26946]: saned from sane-backends 1.0.11 ready
Aug 25 14:55:26 router saned[26946]: check_host: access by remote host: 192.168.0.250
Aug
2004 Oct 06
9
Problem with local email after shorewall installation
Hi,
Summary of problem:
Local mail on the firewall stopped working after installing shorewall
Background
yesterday I installed shorewall, based on the debian package from
www.backports.org
(which seems to be a 2.0.3 package) on an otherwise virgin debian woody set up.
Configuration was done based on the two-interface setup.
Kernel is 2.6.8.1 unpatched. A 2.4.23 kernel, with
2006 Aug 04
4
policy ordering when mixing interface zones and host defined zones
Running shorewall 3.0.6, Linux 2.6.16, iptables 1.3.0.
This firewall has eth1 facing the DMZ and eth0 is a 802.1q trunk
with 6 VLANs and zones on it. I would like to allow one subnet
living out beyond the DMZ to have access to all zones on this firewall.
It seemed that creating a zone would allow for this to be done cleanly via
a line in the policy file. I defined this special subnet as the
2005 Jan 29
2
Problems internet sharing between mandrake 10.1 and XP
Hi
I have recently installed madrake 10.1 on my PC, i wish to connect my
laptop running XP to linux machine mainly for internet sharing.
Linux machine is connected to internet via ADSL USB modem (D Link 200).
I use eciadsl package(driver) for this modem and apparently in the
network interface it comes up as tap0 . I have network card installed
to my PC which comes up as eth0. This network card
2004 Oct 25
2
Strange problem
Hello,
My workstation should synchronize its clock on my server but from some
reason this is not allowed
This is what I get in the log when the client tries to sync with NTP
Oct 25 08:25:47 server kernel: Shorewall:all2all:REJECT:IN= OUT=eth1
SRC=192.168.0.5 DST=192.168.0.4 LEN=76 TOS=0x10 PREC=0x00 TTL=64 ID=0 DF
PROTO=UDP SPT=123 DPT=1031 LEN=56
My internal network is eth1 , external is
2003 Jul 30
9
occasional rejected packets
Hi,
I am getting occasional rejected packets like so:
Jul 31 09:52:03 firewall kernel: Shorewall:all2all:REJECT:IN=eth2
OUT=eth0 SRC=192.168.10.91 DST=132.147.22.6 LEN=48 TOS=0x00 PREC=0x00
TTL=127 ID=55364 DF PROTO=TCP SPT=1147 DPT=23 WINDOW=16384 RES=0x00 SYN
URGP=0
Jul 31 09:52:46 firewall kernel: Shorewall:all2all:REJECT:IN=eth2
OUT=eth0 SRC=192.168.10.26 DST=10.9.100.30 LEN=48 TOS=0x00
2005 Jan 25
3
masc and multicast
I am trying to set up my Shorewall box to forward multicast packets to
my local net. I do have some problems with mrouted (see below), but I
can join and add routes using smcroute. Multicast works when shorewall
is disabled. I got a lot of help from the following.
http://lists.shorewall.net/pipermail/shorewall-users/2005-January/016674.html
I cannot get the multicast packets to pass the fw when
2002 May 30
3
eDonkey and Shorewall
Hi everybody!
I''m very happy with shorewall, seems to safe my computer well, a little
bit to well. But i''m sure it''s a mistake of mine:
I can''t get edonkey working! They say that edonkey needs the following
ports enabled:
4665 udp in / out
3665,4665,7665,8665 udp out
4661,4662,4666 tcp in
thats what i wrote in the rules file:
ACCEPT fw net
2003 Mar 23
12
Shorewall 1.4.1
This is a minor release of Shorewall.
WARNING: This release introduces incompatibilities with prior releases.
See http://www.shorewall.net/upgrade_issues.htm.
Changes are:
a) There is now a new NONE policy specifiable in
/etc/shorewall/policy. This policy will cause Shorewall to assume that
there will never be any traffic between the source and destination
zones.
b) Shorewall no longer
2003 Mar 28
9
Squid
I''m attempting to setup Squid as shown on:
http://shorewall.sourceforge.net/Shorewall_Squid_Usage.html#DMZ
The firewall is a Bering 1.0 firewall running Shorewall 1.3.11, Red Hat
7.2 on the server in the DMZ. I''m not seeing the requests come in to the
server using tcpdump. The server is 192.168.2.1 connecting to eth2 on the
firewall, the local traffic I''m trying to
2006 Apr 12
2
DCC transfers don't work, but IRC works
Hi!
Already searched for it and asked in IRC channel but all replies talk
about ip_conntrack_irc and ip_nat_irc.
I have a rule in 'NEW' section of 'shorewall/rules' to irc:
ACCEPT fw net tcp 6667 #IRC
and 'lsmod|grep irc' shows:
ip_nat_irc 3648 0
ip_nat 22572 8 [...]
ip_conntrack_irc