Re: [Shorewall-users] Port Forwarding

2011-03-17 Thread CACook
On Monday 7 March, 2011 07:55:39 Tom Eastep wrote: > First of all, your rules are wrong. You want a single rule: > > DNAT net cam:10.5.12.40 tcp www Thanks, but it's not working. Everything's set like you say, but when I try from another machine: [515690.154919] Shorewall:FOR

Re: [Shorewall-users] Port Forwarding

2011-03-17 Thread Tom Eastep
On 3/17/11 9:05 AM, cac...@quantum-sci.com wrote: > On Monday 7 March, 2011 07:55:39 Tom Eastep wrote: >> First of all, your rules are wrong. You want a single rule: >> >> DNAT net cam:10.5.12.40 tcp www > > Thanks, but it's not working. Everything's set like you say, but > when

Re: [Shorewall-users] Port Forwarding

2011-03-17 Thread CACook
> Your routing is wrong. Note that it is trying to route the packet back > out of eth0. > > How have you configured eth2? Noticed that, but don't know why. (Debian Testing) I've deinstalled network-manager and manually edit /etc/network/interfaces like I always have: allow-hotplug eth2 iface e

Re: [Shorewall-users] Port Forwarding

2011-03-17 Thread Tom Eastep
On 3/17/11 10:49 AM, cac...@quantum-sci.com wrote: >> Your routing is wrong. Note that it is trying to route the packet back >> out of eth0. >> >> How have you configured eth2? > > Noticed that, but don't know why. (Debian Testing) I've deinstalled > network-manager and manually edit /etc/netwo

Re: [Shorewall-users] Port Forwarding

2011-03-17 Thread CACook
On Thursday 17 March, 2011 11:09:56 Tom Eastep wrote: > The camera is at 10.5.42.40 but your DNAT rule says 10.5.12.40. Oh, FFS. Don't tell me it's that particular... OK, so I believe that all the ports the camera presents are now on 192.168.1.4. Is there a way to map the ports the camera pres

[Shorewall-users] DNAT problem

2011-03-17 Thread Always GNU
Hi All, I use rather old Shorewall 3.2.6 and I know it's no longer supported. I haven't been updating the software because it works as intended until now. The problem is a simple DNAT rule. I actually have around 8 DNAT rules and they all work just fine. Here is what I want to achieve. I have a

Re: [Shorewall-users] DNAT problem

2011-03-17 Thread Tom Eastep
On 3/17/11 3:45 PM, Always GNU wrote: > > What's goin on? > I suggest that you follow the DNAT troubleshooting tips in FAQs 1a and 1b and find out. My bet is that port 25 is being blocked before it gets to the Shorewall box. -Tom -- Tom Eastep\ When I die, I want to go like my Grandfa

Re: [Shorewall-users] Port Forwarding

2011-03-17 Thread Tom Eastep
On 3/17/11 3:07 PM, cac...@quantum-sci.com wrote: > On Thursday 17 March, 2011 11:09:56 Tom Eastep wrote: >> The camera is at 10.5.42.40 but your DNAT rule says 10.5.12.40. > > Oh, FFS. Don't tell me it's that particular... :-) > > OK, so I believe that all the ports the camera presents are no

[Shorewall-users] Attached shorewall dumps

2011-03-17 Thread Jay Ridgley
Folks, I have been able to get my routing straight (at least I think so), however, at the point in time when I try to bring up my browser(Firefox) or email (Thunderbird) my lap top looses connectivity to my network. The route display and netstat -rn appear to contain what I expect. I am attach

Re: [Shorewall-users] Attached shorewall dumps

2011-03-17 Thread Tom Eastep
On 3/17/11 4:38 PM, Jay Ridgley wrote: > > OLD runs Ubuntu 8.04 LTS and NEW runs Ubuntu 10.04.2 LTS Shorewall > versions are 4.0 and 4.4 respectively. > > Both systems have three interfaces(net, local and wireless). > > Here is what is happening I can ping -c3 yahoo.com no problem. From where

Re: [Shorewall-users] Attached shorewall dumps

2011-03-17 Thread Jay Ridgley
On 03/17/2011 07:10 PM, Tom Eastep wrote: > On 3/17/11 4:38 PM, Jay Ridgley wrote: > >> >> OLD runs Ubuntu 8.04 LTS and NEW runs Ubuntu 10.04.2 LTS Shorewall >> versions are 4.0 and 4.4 respectively. >> >> Both systems have three interfaces(net, local and wireless). >> >> Here is what is happening

Re: [Shorewall-users] Attached shorewall dumps

2011-03-17 Thread Tom Eastep
On 3/17/11 7:36 PM, Jay Ridgley wrote: > On 03/17/2011 07:10 PM, Tom Eastep wrote: >> On 3/17/11 4:38 PM, Jay Ridgley wrote: >> >>> >>> OLD runs Ubuntu 8.04 LTS and NEW runs Ubuntu 10.04.2 LTS Shorewall >>> versions are 4.0 and 4.4 respectively. >>> >>> Both systems have three interfaces(net, local

Re: [Shorewall-users] Attached shorewall dumps

2011-03-17 Thread Tom Eastep
On 3/17/11 7:36 PM, Jay Ridgley wrote: > All other connections are wired and within the range 192.168.139.0/28 > > subnet 192.168.139.0 netmask 255.255.255.240 { >option routers 192.168.139.2; >option subnet-mask 255.255.255.240; >option domain-name-servers 24.