Re: [Shorewall-users] Multi-ISP question

2011-12-04 Thread Lee Brown
On Wed, Nov 30, 2011 at 5:00 PM, Tom Eastep wrote: > On Wed, 2011-11-30 at 12:23 -0800, Lee Brown wrote: > > On Wed, Nov 30, 2011 at 10:47 AM, Tom Eastep > > wrote: > > > What exactly is your concern with connection tracking? Can't you > > simply disable the interface to ISP#1 when the limit is

[Shorewall-users] Shorewall 4.4.27 Beta 1

2011-12-04 Thread Tom Eastep
Beta 1 is now available for testing. One of the problems I've had with the Shorewall products is trying to keep them all in sync. There have been two copies of each shell library and four CLI programs. To simplify maintenance, I have collapsed each of the library pairs into a single library an

Re: [Shorewall-users] See dmz sites from Inside dmz

2011-12-04 Thread Tom Eastep
On Sun, 2011-12-04 at 08:34 -0500, Casey Bralla wrote: > There is probably a simple solution to this, but I think I've wrapped > myself up in my underwear and can't see my way > > I'm trying to get to web sites on my DMZ from other machines on my DMZ, by > using the external IP. This fails with

[Shorewall-users] See dmz sites from Inside dmz

2011-12-04 Thread Casey Bralla
There is probably a simple solution to this, but I think I've wrapped myself up in my underwear and can't see my way I'm trying to get to web sites on my DMZ from other machines on my DMZ, by using the external IP. This fails with a timeout error. I'm running a 3-interface Shorewall 3.2.6 on D