[Shorewall-users] Blocked host getting through

2011-11-30 Thread Kilburn Abrahams
Hi, Using 4.4.23.2 on a single host. A host x.x.x.x is sending traffic although it blacklisted and blocked rules rules: DROPnet:x.x.x.x/21 $FW - - - DROPnet:x.x.x.x/22 $FW - - - DROP$FW net

Re: [Shorewall-users] Multi-ISP question

2011-11-30 Thread Tom Eastep
On Wed, 2011-11-30 at 12:23 -0800, Lee Brown wrote: > On Wed, Nov 30, 2011 at 10:47 AM, Tom Eastep > wrote: > What exactly is your concern with connection tracking? Can't you > simply disable the interface to ISP#1 when the limit is reached? > > > The problem I find with that is once I bring th

Re: [Shorewall-users] Multi-ISP question

2011-11-30 Thread Lee Brown
On Wed, Nov 30, 2011 at 10:47 AM, Tom Eastep wrote: > > On Nov 29, 2011, at 7:32 PM, Lee Brown wrote: > > I currently have a multi-ISP config and it's working great. Host is a > CentOS5.4 machine. Shorewall 4.4.19.1 > > I've been asked to add a new ISP which has a 1GB download limit during > cer

Re: [Shorewall-users] Multi-ISP question

2011-11-30 Thread Tom Eastep
On Nov 29, 2011, at 7:32 PM, Lee Brown wrote: > I currently have a multi-ISP config and it's working great. Host is a > CentOS5.4 machine. Shorewall 4.4.19.1 > > I've been asked to add a new ISP which has a 1GB download limit during > certain hours. When the cap is hit my users want to switc