Re: [Shorewall-users] shorewall6 ipv6 does not support BROADCAST matching

2013-11-11 Thread Bruce S. Skinner
Thanks Tom, that clears up all the questions I had. regards :-) BruceS Tom Eastep writes: > On 11/10/2013 6:00 PM, Bruce S. Skinner wrote: >> Gentlepeople, >> >> Shorewall6 starts successfully, but during: >> Compiling /usr/share/shorewall6/action.Broadcast for chain Broadcast... >> >> the

[Shorewall-users] Shorewall and fwsnort

2013-11-11 Thread Sander Klein
Hi, This has been asked on the list before, but is there a way to integrate shorewall and fwsnort? It would be nice to be able to use it somehow. Regards, Sander -- November Webinars for C, C++, Fortran Developers Acc

Re: [Shorewall-users] Help with Shorewall Traffic Shaping

2013-11-11 Thread Tom Eastep
On 11/11/2013 4:57 AM, JC Putter wrote: > Hi, > > anyone that can maybe assist? > > Thanks > > > On Sun, Nov 10, 2013 at 9:39 AM, JC Putter > wrote: > > Hi, > > i am using shorewall 4.5.21.3 on CentOS 6.4. i have a two interface > firewall, one wan and

Re: [Shorewall-users] shorewall6 ipv6 does not support BROADCAST matching

2013-11-11 Thread Tom Eastep
On 11/10/2013 6:00 PM, Bruce S. Skinner wrote: > Gentlepeople, > > Shorewall6 starts successfully, but during: > Compiling /usr/share/shorewall6/action.Broadcast for chain Broadcast... > > the kernel issues the message: > xt_addrtype: ipv6 does not support BROADCAST matching That message is t

Re: [Shorewall-users] Martians on a Multiple uplinks

2013-11-11 Thread Tom Eastep
On 11/11/2013 2:12 AM, Kilburn Abrahams wrote: > On 11/11/2013 02:55 AM, Tom Eastep wrote: >> On 11/10/2013 2:37 AM, Kilburn Abrahams wrote: >>> Hi >>> >>> I got a server with dual nics. Each nic is connected to an dsl gateway. >>> This is essentially a dual standalone system with a single network

Re: [Shorewall-users] Help with Shorewall Traffic Shaping

2013-11-11 Thread JC Putter
Hi, anyone that can maybe assist? Thanks On Sun, Nov 10, 2013 at 9:39 AM, JC Putter wrote: > Hi, > > i am using shorewall 4.5.21.3 on CentOS 6.4. i have a two interface > firewall, one wan and the another lan. > > the firewall is doing masquerading for the lan, i am trying to setup some > QoS

Re: [Shorewall-users] Clarification Question Re: Traffic Shaping

2013-11-11 Thread Johannes Graumann
Tom Eastep wrote: > On 11/10/2013 1:27 AM, Johannes Graumann wrote: >> Hello, >> >> Does >> >>> "Simple traffic shaping is only useful on interfaces where queuing >>> occurs. As a consequence, internal interfaces seldom benefit from simple >>> traffic shaping." >> > > That was true only up unt

Re: [Shorewall-users] Martians on a Multiple uplinks

2013-11-11 Thread Kilburn Abrahams
On 11/11/2013 02:55 AM, Tom Eastep wrote: > On 11/10/2013 2:37 AM, Kilburn Abrahams wrote: >> Hi >> >> I got a server with dual nics. Each nic is connected to an dsl gateway. >> This is essentially a dual standalone system with a single network >> interface, but all Ethernet cables is using 1 switc

Re: [Shorewall-users] masq and https question

2013-11-11 Thread Johannes Graumann
Tom Eastep wrote: > On 11/10/2013 4:56 AM, Johannes Graumann wrote: >> Hello, >> >> I am running a server with one external NIC and a bridge that serves a >> bunch of lxc containers. >> >> That bridge/NIC masqerades as the external NIC via a masq file entry. >> >> One of the lxc containers runs