Re: [Shorewall-users] OpenVPN (bridge) -- is this a shorewall issue?

2008-02-18 Thread Tom Eastep
Scott Ruckh wrote: So at this point I believe shorewall is out of the picture because any traffic going to a.b.c.0/24 should be going through the encrypted tunnel and shorewall would not do any filtering on this traffic. Is this a correct assumption? Yes. I just want to make sure I am fo

Re: [Shorewall-users] ERROR: Can't determine the IP address of ppp0

2008-02-18 Thread Brian J. Murrell
On Tue, 2008-02-12 at 19:29 -0600, Jerry Vonau wrote: > > My what you miss when your sleeping... > > If your talking init scripts here, right? Well, initscripts in terms of any of /etc/init.d, /sbin/dhclient-script /etc/ppp/ip-up[.d] and so forth, yes. > The issues I found with > dealing with

Re: [Shorewall-users] OpenVPN (bridge) -- is this a shorewall issue?

2008-02-18 Thread Scott Ruckh
This is what you said Tom Eastep > Scott Ruckh wrote: > >> >> So at this point I believe shorewall is out of the picture because any >> traffic going to a.b.c.0/24 >> should be going through the encrypted tunnel and shorewall would not do any >> filtering on this >> traffic. >> Is this a correct

[Shorewall-users] IP masquerade

2008-02-18 Thread Sébastien WENSKE
Hi all, I've problems to masquerade specific source to specific destination; I explain. I will that any WAN hosts as source (coming through wan interface eth1) to a network (10.147.0.0/16) reachable by eth2 be masquerade. masq file : eth1 eth2 eth1 eth3 eth2:172.17.0.0/16 eth1:0.0.0.0/0

[Shorewall-users] Advice on vlans and pppoe

2008-02-18 Thread Chris Mason (Lists)
My telco is moving to feeding me over fiber, breaking out with a media converter to one Ethernet interface. At present, I am retaining the static feed over copper on eth0, and taking the two new feeds via vlans on eth1. I have configured the static IP feed on eth1:790 as vlan 790, and that seem

Re: [Shorewall-users] Advice on vlans and pppoe

2008-02-18 Thread Michael Loftis
--On February 18, 2008 5:56:21 PM -0400 "Chris Mason (Lists)" <[EMAIL PROTECTED]> wrote: > My telco is moving to feeding me over fiber, breaking out with a media > converter to one Ethernet interface. At present, I am retaining the > static feed over copper on eth0, and taking the two new feeds

Re: [Shorewall-users] Advice on vlans and pppoe

2008-02-18 Thread Tom Eastep
Chris Mason (Lists) wrote: > The traffic come to me with 802.1q encapsulation, two vlans on one > interface. 780 is the pppoe adsl feed, 790 is the static IP. I was able > to bring the 790 feed up first, and it works as an interface if I ping > it and ping the gateway for that network, but I nev

Re: [Shorewall-users] Advice on vlans and pppoe

2008-02-18 Thread Chris Mason (Lists)
The traffic come to me with 802.1q encapsulation, two vlans on one interface. 780 is the pppoe adsl feed, 790 is the static IP. I was able to bring the 790 feed up first, and it works as an interface if I ping it and ping the gateway for that network, but I never got it to work in Shorewall. W

Re: [Shorewall-users] Advice on vlans and pppoe

2008-02-18 Thread Tom Eastep
Chris Mason (Lists) wrote: > My telco is moving to feeding me over fiber, breaking out with a media > converter to one Ethernet interface. At present, I am retaining the > static feed over copper on eth0, and taking the two new feeds via vlans > on eth1. I have configured the static IP feed on e

Re: [Shorewall-users] ERROR: Can't determine the IP address of ppp0

2008-02-18 Thread Jerry Vonau
Brian J. Murrell wrote: Hey you updated the /sbin/dhclient-script in 1999. > On Tue, 2008-02-12 at 19:29 -0600, Jerry Vonau wrote: >> My what you miss when your sleeping... >> >> If your talking init scripts here, right? > > Well, initscripts in terms of any > of /etc/init.d, /sbin/dhclient-scri