Re: [Shorewall-users] Problem SIP

2013-10-01 Thread Simon Hobson
Orlandinei Vujanski wrote: > I have some users that connect via Softphone (SIP) outside my network. > I've done a DNAT rule correctly. > When these users connect, they can hear, but the other side can not hear. > My telephony server receives connections by an alias eth0: 4 which is the > same IP o

[Shorewall-users] Null-route RFC 5737, 4193, 3849

2013-10-01 Thread Mark van Dijk
Hi Tom, list members, Shorewall has NULL_ROUTE_RFC1918. I'd like to propose another one: NULL_ROUTE_RFC5737. This RFC describes the address ranges that are reserved for documentation. Quoting from https://tools.ietf.org/html/rfc5737: "The blocks 192.0.2.0/24 (TEST-NET-1), 198.51.100.0/24 (TEST-N

Re: [Shorewall-users] Advise sought on strategy to allow selective web access (distribution repositories)

2013-10-01 Thread Johannes Graumann
Johannes Graumann wrote: > Hello, > > I'm running shorewall 4.5.5.3 on a debian wheezy server which serves as > the host to a number of lxc containers sequestering services (nginx, > plone, kolab3, ...). > > Http access to the containers is all managed by nginx, but for updates of > e.g. package

Re: [Shorewall-users] Null-route RFC 5737, 4193, 3849

2013-10-01 Thread Mark van Dijk
> And while on the topic; perhaps for IPv6/shorewall6 there can be a > NULL_ROUTE_RFC4193 and NULL_ROUTE_RFC3849 that would null-route > respectively the fc00::/7 range which is reserved for Unique Local IPv6 > Unicast Addresses, and the 2001:DB8::/32 range which is reserved for > documentation.

Re: [Shorewall-users] Advise sought on strategy to allow selective web access (distribution repositories)

2013-10-01 Thread Johannes Graumann
Johannes Graumann wrote: > Johannes Graumann wrote: > >> Hello, >> >> I'm running shorewall 4.5.5.3 on a debian wheezy server which serves as >> the host to a number of lxc containers sequestering services (nginx, >> plone, kolab3, ...). >> >> Http access to the containers is all managed by ngi

Re: [Shorewall-users] strange problem

2013-10-01 Thread Hristo Benev
Indeed it was routing. Thanks for the pointer Tom. > Оригинално писмо >От: Tom Eastep teas...@shorewall.net >Относно: Re: [Shorewall-users] strange problem >До: shorewall-users@lists.sourceforge.net >Изпратено на: Вторник, 2013, Октомври 1 03:51:00 EEST > On