[Shorewall-users] Extended MARK Target Question.

2007-07-16 Thread Harry Lachanas
Hi all, I got a bit confused with "Extended MARK Target" Is this capability available with 2.4.xx kernels ??? If yes which module is required?? Thanks, Regards Harry - This SF.net email is sponsored by DB2 Express Download

Re: [Shorewall-users] Extended MARK Target Question.

2007-07-16 Thread Tom Eastep
Harry Lachanas wrote: > Hi all, > > I got a bit confused with "Extended MARK Target" > > Is this capability available with 2.4.xx kernels ??? I have no idea. -Tom -- Tom Eastep\ Nothing is foolproof to a sufficiently talented fool Shoreline, \ http://shorewall.net Washington USA \ [EM

Re: [Shorewall-users] Extended MARK Target Question.

2007-07-16 Thread Tom Eastep
Tom Eastep wrote: > Harry Lachanas wrote: >> Hi all, >> >> I got a bit confused with "Extended MARK Target" >> >> Is this capability available with 2.4.xx kernels ??? > > I have no idea. I suspect that the LEAF list is a better place to get this question answered since the Bering developers are m

Re: [Shorewall-users] No Startup at Boot

2007-07-16 Thread Tuomo Soini
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Tom Eastep wrote: > Andrew Suffield wrote: >> It's an unfortunate >> concidence that shorewall has a feature that duplicates part of the >> behaviour of the init script. > > In hindsight, it was an unfortunate choice on my part. Using > /etc/default/s

Re: [Shorewall-users] No Startup at Boot

2007-07-16 Thread Tom Eastep
Tuomo Soini wrote: > Tom Eastep wrote: >> Andrew Suffield wrote: >>> It's an unfortunate >>> concidence that shorewall has a feature that duplicates part of the >>> behaviour of the init script. >> In hindsight, it was an unfortunate choice on my part. Using >> /etc/default/shorewall or /etc/syscon

Re: [Shorewall-users] smtp etc not going through in multiisp setup

2007-07-16 Thread Tom Eastep
Tom Eastep wrote: > Kenneth Gonsalves wrote: >> Now I have to add a third isp - >> what will the masq file look like then? >> > > For each of N firewall external addresses, you need to consider what > happens if a connection with that address as SOURCE is sent out of each > of M external interfa

Re: [Shorewall-users] No Startup at Boot

2007-07-16 Thread Tom Eastep
Roberto C. Sánchez wrote: > On Sun, Jul 15, 2007 at 02:44:18PM -0700, Tom Eastep wrote: >> Andrew Suffield wrote: >>> It's an unfortunate >>> concidence that shorewall has a feature that duplicates part of the >>> behaviour of the init script. >> In hindsight, it was an unfortunate choice on my par

Re: [Shorewall-users] smtp etc not going through in multiisp setup

2007-07-16 Thread Kenneth Gonsalves
On 16-Jul-07, at 11:56 PM, Tom Eastep wrote: >> >> Follow the above advice and it will work for N external addresses >> on M >> external interfaces with L internal LANs for all values of L, M >> and N. > > I've added a section to http://www1.shorewall.net/MultiISP.html > which should > clar

Re: [Shorewall-users] smtp etc not going through in multiisp setup

2007-07-16 Thread Tom Eastep
Kenneth Gonsalves wrote: > > [EMAIL PROTECTED] lawgon]# ip route ls > 202.71.146.208/28 dev eth1 proto kernel scope link src > 202.71.146.210 metric 5 > 192.168.2.0/24 dev eth0 proto kernel scope link src 192.168.2.201 > metric 5 > 192.168.10.0/24 dev eth2 proto kernel scope link s

Re: [Shorewall-users] smtp etc not going through in multiisp setup

2007-07-16 Thread Kenneth Gonsalves
On 17-Jul-07, at 7:18 AM, Tom Eastep wrote: >> i am worried about the last line - eth3 is an unreliable ISP, but it >> is shown as default. I want eth1 as default. I have listed eth3 last >> in every config, so how do I prevent it from being the default. > > I don't know -- Shorewall isn't doing