Re: [Shorewall-users] L7-Filter

2007-11-27 Thread shacky
> However, if you want to use L7-filter, just use the NFQUEUE target in > Shorewall-perl 4.0.6 to send the traffic you want to be filtered by > L7-flter to NFQUEUE. So are you advising me to use ipp2p? Some people told me that L7-Filter is better than ipp2p, and I like it because it can recognise

Re: [Shorewall-users] 回覆: Re: 回覆: Re: ? ??嚗?Re: ???嚗?Re: ?????Re: ???嚗?Re: Port 3001 still have problem

2007-11-27 Thread Tom Eastep
Wilson Kwok wrote: > Tom, > > 1. I asked the vendor that they had setup this video conference software in > others company was no problem with NATed. > > 2. Becuase the video conference software can use web-interface for > client login , so server side required Windows IIS for it, the default >

Re: [Shorewall-users] L7-Filter

2007-11-27 Thread Tom Eastep
shacky wrote: > Could you help me to understand how to use L7-Filter with the NFQUEUE > features of Shorewall, please? Sorry -- I looked at the L7-Filter documentation enough to understand that it uses NFQUEUE and that's all that I have the time or the interest to do. The basic idea should be tha

[Shorewall-users] problem with multiple masking

2007-11-27 Thread Christian Vieser
Hi all, after a half day searching for an error, sniffing and upgrading to the newest shorewall version I give up and the problem to you. I have following configuration in my /etc/shorewall/masq: #INTERFACE SOURCEADDRESS vlan7::10.231.0.0/16 192.168.222.0/24

Re: [Shorewall-users] problem with multiple masking

2007-11-27 Thread Tom Eastep
Christian Vieser wrote: > Hi all, > > after a half day searching for an error, sniffing and upgrading to the > newest shorewall version I give up and the problem to you. I have > following configuration in my /etc/shorewall/masq: > > #INTERFACE SOURCEADDRESS > v

[Shorewall-users] Port Redirecting on single system

2007-11-27 Thread Jean-Philippe Steinmetz
Hi all, I'm a newbie to shorewall. I'm trying to set up a redirection for Tomcat from port 80 to 8180 on my debian box. I've seen lots of examples for using nat to other computers within a network but nothing for redirecting within the same machine. This box is setup to just have a basic single-N

Re: [Shorewall-users] Port Redirecting on single system

2007-11-27 Thread Roberto C . Sánchez
On Tue, Nov 27, 2007 at 04:27:15PM -0800, Jean-Philippe Steinmetz wrote: > Hi all, > > I'm a newbie to shorewall. I'm trying to set up a redirection for Tomcat > from port 80 to 8180 on my debian box. I've seen lots of examples for using > nat to other computers within a network but nothing for r

Re: [Shorewall-users] port forwarding on a single ip

2007-11-27 Thread Jean-Philippe Steinmetz
Roberto C. Sánchez connexer.com> writes: > > On Wed, Nov 21, 2007 at 08:31:15PM +0100, Stéphane Gully wrote: > > > > You just need this rule: > > > > > > > > REDIRECT net 40240 tcp 80 - 87.145.23.55 Thanks Roberto for pointing this thread out. I just have one question,

Re: [Shorewall-users] port forwarding on a single ip

2007-11-27 Thread Roberto C . Sánchez
On Wed, Nov 28, 2007 at 12:38:07AM +, Jean-Philippe Steinmetz wrote: > Roberto C. Sánchez connexer.com> writes: > > > > > On Wed, Nov 21, 2007 at 08:31:15PM +0100, Stéphane Gully wrote: > > > > > You just need this rule: > > > > > > > > > > REDIRECT net 40240 tcp 80 -

Re: [Shorewall-users] port forwarding on a single ip

2007-11-27 Thread Jean-Philippe Steinmetz
> No. You would need the address for the ORIGINAL DEST column. > In your case, I would recommend my approach. Run apache on > port 80 and the have it use ProxyPass and ProxyPassReverse to > http://127.0.0.1:4/ (or whatever you high-numbered port > is). Then there is no need to involve S

Re: [Shorewall-users] port forwarding on a single ip

2007-11-27 Thread Roberto C . Sánchez
On Tue, Nov 27, 2007 at 05:00:29PM -0800, Jean-Philippe Steinmetz wrote: > > I actually just tried using > > REDIRECT net 40240 tcp 80 - - > > And it appears to have worked. I will continue to further test this but if I > can avoid running apache (no particular reason ot

Re: [Shorewall-users] port forwarding on a single ip

2007-11-27 Thread Tom Eastep
Roberto C. Sánchez wrote: > On Tue, Nov 27, 2007 at 05:00:29PM -0800, Jean-Philippe Steinmetz wrote: >> I actually just tried using >> >> REDIRECT net 40240 tcp 80 - - >> >> And it appears to have worked. I will continue to further test this but if I >> can avoid running ap

Re: [Shorewall-users] port forwarding on a single ip

2007-11-27 Thread Jean-Philippe Steinmetz
> I've not tried that personally. Perhaps Tom or someone else > can comment on whether that is a good idea in the first place. > > Now, this may seem like a dumb question. If you are not > running Apache, then why not just have Tomcat on port 80? > > Regards, > > -Roberto > > -- > Roberto C

Re: [Shorewall-users] port forwarding on a single ip

2007-11-27 Thread Tom Eastep
Jean-Philippe Steinmetz wrote: > I have spent hours searching for ways and > everyone seems to think redirection is the only option. If you know of a way > to get Debian to allow Tomcat to bind at port 80 I would love to know. The behavior you describe is mandated by IEEE 1003.1 (the POSIX standa

Re: [Shorewall-users] port forwarding on a single ip

2007-11-27 Thread Roberto C . Sánchez
On Tue, Nov 27, 2007 at 05:08:09PM -0800, Jean-Philippe Steinmetz wrote: > > Definitely not a dumb question. I would love to run Tomcat on port 80 but I > discovered that (under debian at least) I am unable to run Tomcat as a > non-root user on any port under 1024 (linux security). I am also not v

Re: [Shorewall-users] port forwarding on a single ip

2007-11-27 Thread Luke Heberling
Jean-Philippe Steinmetz wrote: > Definitely not a dumb question. I would love to run Tomcat on port 80 but I > discovered that (under debian at least) I am unable to run Tomcat as a > non-root user on any port under 1024 (linux security). I am also not very > keen on running Tomcat as root. I have