Re: [Shorewall-users] Shorewall and routebacks with default gateway not on firewall

2014-06-24 Thread Tom Eastep
On 6/24/2014 10:48 AM, Gerhard Wiesinger wrote: > Hello, > > I've the following configuration: > Internet <=> Host with fixed IP <=> OpenVPN Tunnel <=> Firewall Host > with dynamic IP <=> DMZ > > Firewall Host with dynamic IP isn't the gateway. > > I've configured: > 1.) "Host with fixed IP" a

Re: [Shorewall-users] Problems with Shorewall 4.6.1.1 and Portknocking Events example

2014-06-24 Thread Gerhard Wiesinger
On 20.06.2014 20:03, Tornhoof wrote: Hi, I previously used (4.5.x, 4.6.0) the following Portknocking configuration (from here http://shorewall.net/Events.html): Please find attached a "real" stateful Port Knocking Module for shorewall. Was quite a challenge to write a stateful iptables "prog

[Shorewall-users] Shorewall and routebacks with default gateway not on firewall

2014-06-24 Thread Gerhard Wiesinger
Hello, I've the following configuration: Internet <=> Host with fixed IP <=> OpenVPN Tunnel <=> Firewall Host with dynamic IP <=> DMZ Firewall Host with dynamic IP isn't the gateway. I've configured: 1.) "Host with fixed IP" a DNAT forward into the OpenVPN Tunnel (OK): SMTP(DNAT) net

Re: [Shorewall-users] rtrule that changed based on time-of-day

2014-06-24 Thread Tom Eastep
On 6/24/2014 9:20 AM, Lee Brown wrote: > On Tue, Jun 24, 2014 at 5:14 AM, Brian J. Murrell > wrote: >> >> On Mon, 2014-06-23 at 08:29 -0700, Tom Eastep wrote: >>> >>> I would be much more willing to add a TIME column to the mangle >>> (formerly tcrules) file. >> >> Fair enough. I just mentioned

Re: [Shorewall-users] rtrule that changed based on time-of-day

2014-06-24 Thread Lee Brown
On Tue, Jun 24, 2014 at 5:14 AM, Brian J. Murrell wrote: > > On Mon, 2014-06-23 at 08:29 -0700, Tom Eastep wrote: > > > > I would be much more willing to add a TIME column to the mangle > > (formerly tcrules) file. > > Fair enough. I just mentioned tcrules since I don't have mangle file > support

Re: [Shorewall-users] NAT problem

2014-06-24 Thread Rodrigo Cortes
Hi :) De: Tom Eastep Enviado: martes, 24 de junio de 2014 11:17 Para: shorewall-users@lists.sourceforge.net Asunto: Re: [Shorewall-users] NAT problem On 6/24/2014 7:13 AM, Rodrigo Cortes wrote: > Hi! > > De: Tom Eas

Re: [Shorewall-users] NAT problem

2014-06-24 Thread Tom Eastep
On 6/24/2014 7:13 AM, Rodrigo Cortes wrote: > Hi! > > De: Tom Eastep > Enviado: jueves, 19 de junio de 2014 10:42 > Para: shorewall-users@lists.sourceforge.net > Asunto: Re: [Shorewall-users] NAT problem > > On 6/19/2014 6:22 AM, Rodrigo Cortes wrote: >> H

Re: [Shorewall-users] NAT problem

2014-06-24 Thread Rodrigo Cortes
Hi! De: Tom Eastep Enviado: jueves, 19 de junio de 2014 10:42 Para: shorewall-users@lists.sourceforge.net Asunto: Re: [Shorewall-users] NAT problem On 6/19/2014 6:22 AM, Rodrigo Cortes wrote: > Hi Tom... > > De: Tom

Re: [Shorewall-users] rtrule that changed based on time-of-day

2014-06-24 Thread Brian J. Murrell
On Mon, 2014-06-23 at 08:29 -0700, Tom Eastep wrote: > > I would be much more willing to add a TIME column to the mangle > (formerly tcrules) file. Fair enough. I just mentioned tcrules since I don't have mangle file support yet because F20 is still shipping 4.5.21.5. Just out of interest, giv