Re: [Shorewall-users] SRC address masquerading over VPN link -- seeing the tunnel endpoint, not the src IP?

2015-05-28 Thread Tom Eastep
On 5/27/2015 8:20 PM, PGNd wrote: > I'm continuing switching from StaticIP network connections to dynamic, > tunneling server traffic to remote VPS' for needed static addressing. > > Redirecting DNS server axfr notifications from a local machine, over an IPv4 > vpn, to a remote/secondary DNS I ha

[Shorewall-users] Shorewall 4.6.10 RC 1

2015-05-28 Thread Tom Eastep
Shorewall 4.6.10 RC 1 is now available for testing. Problems Corrected since Beta 2: 1) Previously, if SAVE_IPSETS=ipv4 (or ipv6) but the configuration did not use ipsets, then a superfluous warning message was issued: WARNING: Invalid value (ipv4) for SAVE_IPSETS That warning is

Re: [Shorewall-users] SRC address masquerading over VPN link -- seeing the tunnel endpoint, not the src IP?

2015-05-28 Thread PGNd
On Thu, May 28, 2015, at 08:13 AM, Tom Eastep wrote: > Is the remote DNS server running on the VPN endpoint server? Yes, the remote DNS is on the remote VPN endpoint server; it's a hosted linux VPS. This DNS will stay this way. Also, the local DNS in on the local VPN endpoint server; it's a stan

Re: [Shorewall-users] SRC address masquerading over VPN link -- seeing the tunnel endpoint, not the src IP?

2015-05-28 Thread Tom Eastep
On 5/28/2015 8:34 AM, PGNd wrote: > On Thu, May 28, 2015, at 08:13 AM, Tom Eastep wrote: >> Is the remote DNS server running on the VPN endpoint server? > Yes, the remote DNS is on the remote VPN endpoint server; it's a hosted linux > VPS. > This DNS will stay this way. > > Also, the local DNS in

Re: [Shorewall-users] canada.shorewall.net FTP server temprary offline

2015-05-28 Thread Hristo Benev
> Оригинално писмо >От: Hristo Benev f...@abv.bg >Относно: [Shorewall-users] canada.shorewall.net FTP server temprary offline >До: Shorewall Users >Изпратено на: 10.04.2015 16:41 > Hi List, > > FTP server on canada.shorewall.net is temporarily down. > > Ther

Re: [Shorewall-users] SRC address masquerading over VPN link -- seeing the tunnel endpoint, not the src IP?

2015-05-28 Thread PGNd
> > May 28 08:06:30 border000 kernel: [34372.977048] SW:fw2vpn1:DROP IN= > > OUT=tun1 SRC=10.0.2.53 DST=10.254.254.1 LEN=143 TOS=0x00 PREC=0x00 TTL=64 > > ID=3671 PROTO=UDP SPT=63068 DPT=53 LEN=123 > Please forward the output of 'shorewall dump' taken after you have > produced the above log

Re: [Shorewall-users] SRC address masquerading over VPN link -- seeing the tunnel endpoint, not the src IP?

2015-05-28 Thread Tom Eastep
On 5/28/2015 2:00 PM, PGNd wrote: >>> May 28 08:06:30 border000 kernel: [34372.977048] SW:fw2vpn1:DROP IN= >>> OUT=tun1 SRC=10.0.2.53 DST=10.254.254.1 LEN=143 TOS=0x00 PREC=0x00 TTL=64 >>> ID=3671 PROTO=UDP SPT=63068 DPT=53 LEN=123 >> Please forward the output of 'shorewall dump' taken after

Re: [Shorewall-users] SRC address masquerading over VPN link -- seeing the tunnel endpoint, not the src IP?

2015-05-28 Thread PGNd
On Thu, May 28, 2015, at 02:20 PM, Tom Eastep wrote: > Remove the vpn1 entry from your masq file. Alas, there's no such entry. local SHOREWALL/masq EXT_IF 10.0.1.0/24 5.6.7.8 remote SHOREWALL/masq (empty) I'm stripping down the example pair of machines to just DNS &

[Shorewall-users] 2 Subnets, 2 Gateways, 1 Interface

2015-05-28 Thread Wesley Channon
Hi there! I'm trying to setup Shorewall 4.5.21.6 on an Ubuntu 14.04 machine, that has 2 subnets provided by my upstream provider, that each have their own gateway. The server only has a single network interface. Example: Range 1: 192.168.1.240/29 - GW: 192.168.1.241 Range 2: 192.168.2.0/28 - GW

Re: [Shorewall-users] SRC address masquerading over VPN link -- seeing the tunnel endpoint, not the src IP?

2015-05-28 Thread Tom Eastep
On 5/28/2015 2:43 PM, PGNd wrote: > > On Thu, May 28, 2015, at 02:20 PM, Tom Eastep wrote: >> Remove the vpn1 entry from your masq file. > Alas, there's no such entry. > > local SHOREWALL/masq > EXT_IF 10.0.1.0/24 5.6.7.8 > > remote SHOREWALL/masq > (empty) > > > I'm stripping

Re: [Shorewall-users] 2 Subnets, 2 Gateways, 1 Interface

2015-05-28 Thread Tom Eastep
On 5/28/2015 3:10 PM, Wesley Channon wrote: > Hi there! > > I'm trying to setup Shorewall 4.5.21.6 on an Ubuntu 14.04 machine, that > has 2 subnets provided by my upstream provider, that each have their own > gateway. The server only has a single network interface. > > Example: > > Range 1: 192.16

Re: [Shorewall-users] SRC address masquerading over VPN link -- seeing the tunnel endpoint, not the src IP?

2015-05-28 Thread PGNd
For this config -- Remote VPS ETH0: 1.2.3.4 DUMMY0: 10.0.1.53 < remote DNS listens/talks on this IP:53 TUN1: 10.254.254.1 -- | | ---

Re: [Shorewall-users] SRC address masquerading over VPN link -- seeing the tunnel endpoint, not the src IP?

2015-05-28 Thread PGNd
On Thu, May 28, 2015, at 03:32 PM, Tom Eastep wrote: > On the remote system, try this masq entry: > vpn1:10.0.2.5310.254.254.110.0.1.53udp,tcp53 Aha, further down in the inbox, and now "independently verified". Thanks! ---