[Shorewall-users] OpenVPN server with Shorewall not working

2015-03-25 Thread Thomas Winkler
Hello,   I really like Shorewall ! Thanks for this piece of software ! I am using Shorewall on an ARM single computer with two NICs running on Debian 7.8 which runs perfectly.     I installed the OpenVPN server on that single computer board and trying to get OpenVPN server running together with S

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-25 Thread Hesham Ahmed
I don't use tunnels file anymore since everything it does can be done with rules or other files. I understand you're running the OpenVPN Server on the same machine as Shorewall, in that case add the following to your rules file and then try connecting: OpenVPN/ACCEPTnet$FW Regards, Hesha

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-25 Thread Robert K Coffman Jr. -Info From Data Corp.
On my OpenVPN server, I'm using openvpn rather than openvpnclient in the tunnels file. - Bob -- Dive into the World of Parallel Programming The Go Parallel Website, sponsored by Intel and developed in partnership with S

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-25 Thread matt darfeuille
If shorewall is on the same box as the openvpn server you need at least to change "openvpnclient" to "openvpnserver". Depending on your shorewall version the rules file is more straightforward! -Matt On 25 Mar 2015 at 17:54, Thomas Winkler wrote: > Hello, >   > I really like Shorewall ! Thank

[Shorewall-users] FALLBACK - MultipleISP

2015-03-25 Thread Nico Pagliaro
Hi everybody, I am installing a new shorewall firewall from version 4.5.0.2 to 4.6.7 in a Centos 6 I need to have a multiple ISP configuration, QoS and fallback or balance option. Well, there is something that obviously I am doing wrong, because it is not working. This is my config: eth0 = 192.16

Re: [Shorewall-users] FALLBACK - MultipleISP

2015-03-25 Thread Hesham Shakil Ahmed
You would need a way to detect link status and enable/disable the link in shorewall accordingly. Manually you can just run: shorewall disable eth1 and when the connection returns shorewall enable eth1 A better solution would be use something like lsm (read here http://shorewall.net/MultiISP.

Re: [Shorewall-users] FALLBACK - MultipleISP

2015-03-25 Thread Nico Pagliaro
Thanks Hesham, I will try it right now. I will let you know. On Wed, Mar 25, 2015 at 3:38 PM, Hesham Shakil Ahmed wrote: > You would need a way to detect link status and enable/disable the link in > shorewall accordingly. > > Manually you can just run: > > shorewall disable eth1 > > and when t

Re: [Shorewall-users] FALLBACK - MultipleISP

2015-03-25 Thread Nico Pagliaro
Which variable can I use to check the ADSL dynamic IP? is this correct? connection { name=ADSL checkip=${SW_PPP0_GATEWAY:-71.231.152.1} device=ppp0 ttl=1 } On Wed, Mar 25, 2015 at 3:46 PM, Nico Pagliaro wrote: > Thanks Hesham, I will try it right now. > I will let you know. > >

[Shorewall-users] ERROR gateway is not reachable provider cannot be started

2015-03-25 Thread Marco Giacomelli
Hi everyone, I've been having a big problem and this is my last resort after googling for days. I used to have a multi-ISP (both modems on a single interface, routing to two different interfaces) setup running, after upgrading shorewall to version 4.6.4.3, among the whole system (debian), the old

[Shorewall-users] 4.5.4 on CentOS 6: problem with DNAT over a two port ethernet bridge

2015-03-25 Thread Damiano Verzulli
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi all! This morning we upgraded one of our firewalls, moving from an old shorewall 4.0.6 to a more current 4.5.4 (CentOS 6.6 RPM - shorewall-4.5.4-1.el6.noarch). Everything went OK, with the exception of some DNAT rules. In short: -