Re: [Shorewall-users] DNAT Problem

2007-05-24 Thread Andrea Fastame
That could do. I hope. Could you be a little more specific, though? in my "interfaces": #ZONE INTERFACE BROADCAST OPTIONS fw firewall net eth0detect routeback and "rules" #ACTION SOURCE DESTPROTO DESTSOURCE ORIGINAL

Re: [Shorewall-users] Regular expression matching ?

2007-05-24 Thread daniel
>> [EMAIL PROTECTED] wrote: >> >>> > Validating interfaces file... ERROR: The routeback option may not be specified on a multi-zone interface >>> > Does someone made a similar setup and can give a few tips ? >> >> You can setup routeback yourself, 'echo 1 > >> /proc/sys/net/ip

Re: [Shorewall-users] MultiISP problems with the track option

2007-05-24 Thread Jerry Vonau
Grant Scheffert wrote: > I've been using Shorewall on an older box for 3 years and it has worked > fabulous. But we've expanded to having 2 ISPs so I'm building a new > Fedora 6 firewall with Shorewall 3.4.2 and 4 NICs. > > I'm having a problem with outgoing connections when I add the track > op

Re: [Shorewall-users] MultiISP problems with the track option

2007-05-24 Thread Grant Scheffert
Sorry, I should have done the dump the first time. You can see it here: http://www.pantheon1.com/grant/shorewalldump.txt Thanks, Grant -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Jerry Vonau Sent: Thursday, May 24, 2007 7:56 AM To: Shorewall Users Su

[Shorewall-users] Problem with ssh limit and scp stalling

2007-05-24 Thread Jonathan Underwood
Hi, I have a very simple server setup, using shorewall as my firewall. I have a line like this at the top of my rules file to allow ssh connections, but limited to 3 connection per minute with a burst rate of 3: SSH/ACCEPT net $FW - - - - 3/min:3

Re: [Shorewall-users] MultiISP problems with the track option

2007-05-24 Thread Jerry Vonau
Jerry Vonau wrote: > Grant Scheffert wrote: >> # Shorewall version 3.4 - Providers File >> # >> #NAMENUMBER MARKDUPLICATE INTERFACE GATEWAY >> OPTIONS COPY >> ISP1 1 1 maineth2216.x.y.33 track,balance >> ETH0 >> ISP2 2 2 ma