Re: [Shorewall-users] About routing

2016-12-20 Thread Luis Felipe Dominguez Vega
Well to the routers i can access because are owns by my VPN provider, but if i do a Source Nat fix the problem?? and how to do that?? THANKS --- Al tanto Ing. Luis Felipe Domínguez Vega Administrador de la Red de Desoft Matanzas GNU/Linux Kernel Develope

Re: [Shorewall-users] About routing

2016-12-20 Thread Tom Eastep
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 12/20/2016 08:07 AM, Luis Felipe Dominguez Vega wrote: > Well to the routers i can access because are owns by my VPN > provider, but if i do a Source Nat fix the problem?? and how to do > that?? THANKS Which version of Shorewall are you runni

Re: [Shorewall-users] About routing

2016-12-20 Thread Luis Felipe Dominguez Vega
Shorewall 5.0.14.1 over debian testing --- Al tanto Ing. Luis Felipe Domínguez Vega Administrador de la Red de Desoft Matanzas GNU/Linux Kernel Developer - rtlwifi kernel module "No es grande aquel que nunca falla, es grande el que nunca se da por vencido…

Re: [Shorewall-users] About routing

2016-12-20 Thread Simon Hobson
Luis Felipe Dominguez Vega wrote: > Well to the routers i can access because are owns by my VPN provider, but if > i do a Source Nat fix the problem?? and how to do that?? I assume you meant to write that you *can't* access them ? Basically, unless they have been given a route to your interna

[Shorewall-users] Shorewall 5.1.0 Beta 2

2016-12-20 Thread Tom Eastep
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Shorewall 5.1.0 Beta 2 is now available for testing. Problems Corrected since Beta 1: 3) An optimizer defect that could result in start/reload/restart failures has been corrected. 4) Previously, when a list of zones appeared in a policy file

Re: [Shorewall-users] About routing

2016-12-20 Thread Luis Felipe Dominguez Vega
Now i test Firewall Builder and put some basic NAT rules and works! (the communication with router in SNMP from local network) so the routers router table is working, but i want do with shorewall, not with fwbuilder. --- Al tanto Ing. Luis Felipe Domíngu

Re: [Shorewall-users] About routing

2016-12-20 Thread Tom Eastep
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 12/20/2016 09:09 AM, Luis Felipe Dominguez Vega wrote: > Shorewall 5.0.14.1 over debian testing > In /etc/shorewall/snat: #ACTIONSOURCE DEST MASQUERADE 10.0.0.0/24 eth1 MASQUERADE 10.0.0.0/24 et

Re: [Shorewall-users] Shorewall 5.1.0 Beta 2

2016-12-20 Thread Luis Felipe Dominguez Vega
Well thanks, i will test it and check --- Al tanto Ing. Luis Felipe Domínguez Vega Administrador de la Red de Desoft Matanzas GNU/Linux Kernel Developer - rtlwifi kernel module "No es grande aquel que nunca falla, es grande el que nunca se da por venci

Re: [Shorewall-users] Shorewall 5.1.0 Beta 2

2016-12-20 Thread Luis Felipe Dominguez Vega
Thanks... configurating the snat file works well [SOLVED]. --- Al tanto Ing. Luis Felipe Domínguez Vega Administrador de la Red de Desoft Matanzas GNU/Linux Kernel Developer - rtlwifi kernel module "No es grande aquel que nunca falla, es grande el que nunc

[Shorewall-users] Another consult

2016-12-20 Thread Luis Felipe Dominguez Vega
Well here i am again I have a problem with IPs, see this: - | Another | | Place |-R1-- (..) (a VPN Provider) --R2 - GW (Shorewall PC) -- My Net - Into the "Another Place" has 10.11.0.0/24 ips throw R1 connect to my R2 router (10.11.1.1), but my net

Re: [Shorewall-users] Another consult

2016-12-20 Thread Robert K Coffman Jr. -Info From Data Corp.
On 12/20/2016 3:24 PM, Luis Felipe Dominguez Vega wrote: > note that i can change the address of "Another Place". This is the solution. - Bob Coffman -- Developer Access Program for Intel Xeon Phi Processors Access to

Re: [Shorewall-users] Another consult

2016-12-20 Thread Luis Felipe Dominguez Vega
But now, there is a pc with shorewall working well, the problem that i installing a new machine that not works, but there is already a PC doing "something" to do that. --- Al tanto Ing. Luis Felipe Domínguez Vega Administrador de la Red de Desoft Matanza

Re: [Shorewall-users] Another consult

2016-12-20 Thread Luis Felipe Dominguez Vega
Well by now, for temporaly fix how i can ACCEPT that martials packets. --- Al tanto Ing. Luis Felipe Domínguez Vega Administrador de la Red de Desoft Matanzas GNU/Linux Kernel Developer - rtlwifi kernel module "No es grande aquel que nunca falla, es grande

[Shorewall-users] icmp timeout packets

2016-12-20 Thread Philip Le Riche
I'm trying to run traceroute from a Raspberry Pi on one side of shorewall through to the Internet on the other, for the purposes of an Internet routing lesson. I can detect some hosts on the far side of shorewall but not as many as I was hoping (possibly due to ISP filtering), even though I didn't

Re: [Shorewall-users] icmp timeout packets

2016-12-20 Thread Tom Eastep
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 12/20/2016 03:08 PM, Philip Le Riche wrote: > I'm trying to run traceroute from a Raspberry Pi on one side of > shorewall through to the Internet on the other, for the purposes of > an Internet routing lesson. > > I can detect some hosts on the

[Shorewall-users] Forwarding on internal interface

2016-12-20 Thread Alex
Hi, I have a two-interface shorewall setup with one side on a 192.168.0.0 network while the other is connected to the Internet via a cable modem. There's a Win10 machine on the internal network that appears to be sending out snmp requests to the network printer, and I can't understand why shorewa

Re: [Shorewall-users] Forwarding on internal interface

2016-12-20 Thread Tom Eastep
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 12/20/2016 04:59 PM, Alex wrote: > Hi, > > I have a two-interface shorewall setup with one side on a > 192.168.0.0 network while the other is connected to the Internet > via a cable modem. > > There's a Win10 machine on the internal network that