Re: [Shorewall-users] "shell" string in configuration files.

2015-01-09 Thread Tom Eastep
On 1/9/2015 5:00 AM, Artur Uszyński wrote: > Hello. > > When I add an ipv4 zone named "shell" (lowercase) I'm getting the > following error: > > Compiling /etc/shorewall/zones... > /bin/sh: ipv4: command not found > ERROR: SHELL Script failed /etc/shorewall/zones (line 25) > > It was

[Shorewall-users] Why is shorewall6 blocking ICMPv6 NS?

2015-01-09 Thread Jan Lühr
Hello folks, I'm lost. For some reason, shorewall6 is blocking ICMPv6 Neighbor Solicitation. Shorewall6 itself is running on one VM host, connecting different LXC-Containers using a bridge (br-guests). NS between guests is blocked :-/. Details: https://gist.github.com/anonymous/a39bf4d5f6c71fa9b

Re: [Shorewall-users] IP objects or group of addresses in rules

2015-01-09 Thread Simon Hobson
Ivica Glavocic wrote: > Is it possible to group those Internet CIDR networks in FROM part of > the rule and use group name so that rules are clear? Yes, use the params file. You can do things like this : params : OfficeLan=192.168.1.0/24,10.0.2.0/24 WiFiLan-192.168.17.0/24 Lans=$OfficeLan,$Wi

[Shorewall-users] "shell" string in configuration files.

2015-01-09 Thread Artur Uszyński
Hello. When I add an ipv4 zone named "shell" (lowercase) I'm getting the following error: Compiling /etc/shorewall/zones... /bin/sh: ipv4: command not found ERROR: SHELL Script failed /etc/shorewall/zones (line 25) It was not happening in previous (very old) versions of Shorewall. I

[Shorewall-users] IP objects or group of addresses in rules

2015-01-09 Thread Ivica Glavocic
Hi all Shorewall 4.5.4 with 2 interfaces, LAN on eth0 and Internet on eth1. We forward number of different ports from Internet interface to internal servers using DNAT rule, it works OK. Problem is that port forward is filtered and allowed for number of Internet subnets in CIDR format, each DN

Re: [Shorewall-users] Providers with same gateway different interface and IP

2015-01-09 Thread Artur Uszyński
W dniu 06.01.2015 o 09:21, heriyanto shell pisze: > Hi All, > > I get mulitple public IP from my ISP, so far i'am just using one, > so i just put one eth in providers file. > Last night i added new network interface I assign another IP that i get from > my ISP > then i try to modify/add config in