[Shorewall-users] FW: ERROR: FOREWARD_CLEAR_MARK=Yes requires MARK Target in your kernel and iptables

2010-10-09 Thread lists65
I just installed Shorewall and did my configuration as an Universal installation and tried to start Shorewall and got the above error. I have Googled the error and tried to find a resolution on the Shorewall site but I was able to find a resolution, if somesome could help me, I would apprec

Re: [Shorewall-users] FW: ERROR: FOREWARD_CLEAR_MARK=Yes requires MARKTarget in your kernel and iptables

2010-10-09 Thread Michael Weickel - iQom Business Services GmbH
This obviously means that your kernel does not support what you are expecting from the config. Either change your config or recompile your kernel with given MARK support either as module or hard integrated. _ Von: list...@gmail.com [mailto:list...@gmail.com] Gesendet: Sonntag, 10.

Re: [Shorewall-users] FW: ERROR: FOREWARD_CLEAR_MARK=Yes requires MARK Target in your kernel and iptables

2010-10-09 Thread Tom Eastep
On 10/10/10 7:52 AM, list...@gmail.com wrote: > > I just installed Shorewall and did my configuration as an Universal > installation and tried to start Shorewall and got the above error. I > have Googled the error and tried to find a resolution on the Shorewall > site but I was able to find a re

Re: [Shorewall-users] FW: ERROR: FOREWARD_CLEAR_MARK=Yes requires MARK Target in your kernel and iptables

2010-10-09 Thread Tom Eastep
On 10/9/10 9:18 AM, Tom Eastep wrote: > On 10/10/10 7:52 AM, list...@gmail.com wrote: >> >> I just installed Shorewall and did my configuration as an Universal >> installation and tried to start Shorewall and got the above error. I >> have Googled the error and tried to find a resolution on the

[Shorewall-users] setup standalone interface shorewall on an untrusted lan

2010-10-09 Thread mike lan
Hello I'm a newbie shorewall user , trying to setup shorewall on an untrusted lan network where I only connect to proxy server 8080 port and a website at port 8080 and drop any other ip on the lan how to do that with shorewall ? thanks taking time to reply ---

Re: [Shorewall-users] setup standalone interface shorewall on an untrusted lan

2010-10-09 Thread Rodolfo Pilas
El sáb, 09-10-2010 a las 19:24 +, mike lan escribió: > Hello > I'm a newbie shorewall user , trying to setup shorewall on an > untrusted lan network where I only connect to proxy server 8080 port > and a website at port 8080 > and drop any other ip on the lan Place here your files policy

Re: [Shorewall-users] setup standalone interface shorewall on an untrusted lan

2010-10-09 Thread Christ Schlacta
sounds pretty simple, your policy file should only have allalldrop and your rules should have something like ACCEPTsrcdesttcp8080 replace src and dest with the appropriate src and dest, or use 0.0.0.0/0 to let anything from or to anywhere on port 8080 pass. anything el