Re: [Shorewall-users] Shorewall and port 465,587,993,995 not open

2017-02-17 Thread Zenny
Dear Tom, Please find attached the output of the 'shorewall dump' for your review. Cced to you in case the mailinglist does not allow attachment. Thanks in advance. Wbr, /z On 2/15/17, Tom Eastep wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On 02/15/2017 01:12 AM, Zenny wrote

Re: [Shorewall-users] shorewall6 not starting on gentoo

2017-02-17 Thread Phil Stracchino
On 02/17/17 15:26, Benny Pedersen wrote: > Thomas Deutschmann skrev den 2017-02-17 15:45: > >> Yes, I am here :) >> >> But I do not understand your problem. What's your problem with >> shorewall and shorewall6 both providing "firewall"? > > problem is that default openrc have default rc.conf that

Re: [Shorewall-users] Accounting problem - am I missing something simple ?

2017-02-17 Thread Simon Hobson
Tom Eastep wrote: >> I feel some experimentation to see if (manually added) accounting >> rules will work in the Rawpost chain ... >> > > Beware that the rawpost table has been removed in recent kernels. It > was used for stateless SNAT which is now done in the mangle table. Pity, it would hav

Re: [Shorewall-users] shorewall6 not starting on gentoo

2017-02-17 Thread Benny Pedersen
Thomas Deutschmann skrev den 2017-02-17 15:45: > Yes, I am here :) > > But I do not understand your problem. What's your problem with > shorewall and shorewall6 both providing "firewall"? problem is that default openrc have default rc.conf that here does not start shorewall6 so it for me not s

Re: [Shorewall-users] shorewall6 not starting on gentoo

2017-02-17 Thread Phil Stracchino
On 02/17/17 11:17, Thomas Deutschmann wrote: > On 2017-02-17 17:10, Phil Stracchino wrote: >> On 02/16/17 17:23, Tom Eastep wrote: >>> Which init system is the system using? > >> Gentoo uses OpenRC. > > No, the question was right. Gentoo is about choices. You can currently > use OpenRC or systemd

[Shorewall-users] Shorewall 5.1.2 Beta 2

2017-02-17 Thread Tom Eastep
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Shorewall 5.1.2 Beta 2 is now available for testing. Problems Corrected since Beta 1: 1) Deprecated macros and actions are installed in ${SHAREDIR}/shorewall[6]/deprecated/. Previously, the tarball installer did not remove the existing mac

Re: [Shorewall-users] Accounting problem - am I missing something simple ?

2017-02-17 Thread Tom Eastep
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 02/17/2017 12:17 AM, Simon Hobson wrote: > Tom Eastep wrote: > >> -BEGIN PGP SIGNED MESSAGE- >>> The diagram is useful, but doesn't show where accounting rules >>> fit into it. >> >> It actually does. With ACCOUNTING_TABLE=mangle, all r

Re: [Shorewall-users] Accounting problem - am I missing something simple ?

2017-02-17 Thread Matt Darfeuille
On 2/17/2017 4:43 PM, Simon Hobson wrote: > wrote: > >> I feel some experimentation to see if (manually added) accounting rules will >> work in the Rawpost chain ... > > s/chain/table/ > > Well that didn't take long. Seems the rawpost table isn't installed by > default (at least on the Debian

Re: [Shorewall-users] shorewall6 not starting on gentoo

2017-02-17 Thread Thomas Deutschmann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2017-02-17 17:10, Phil Stracchino wrote: > On 02/16/17 17:23, Tom Eastep wrote: >> Which init system is the system using? > > Gentoo uses OpenRC. No, the question was right. Gentoo is about choices. You can currently use OpenRC or systemd. - -

Re: [Shorewall-users] shorewall6 not starting on gentoo

2017-02-17 Thread Phil Stracchino
On 02/16/17 17:23, Tom Eastep wrote: > Which init system is the system using? Gentoo uses OpenRC. -- Phil Stracchino Babylon Communications ph...@caerllewys.net p...@co.ordinate.org Landline: 603.293.8485 signature.asc Description: OpenPGP digital signature

Re: [Shorewall-users] Accounting problem - am I missing something simple ?

2017-02-17 Thread Simon Hobson
wrote: > I feel some experimentation to see if (manually added) accounting rules will > work in the Rawpost chain ... s/chain/table/ Well that didn't take long. Seems the rawpost table isn't installed by default (at least on the Debian systems I work with). it's available in the xtables-addo

Re: [Shorewall-users] shorewall6 not starting on gentoo

2017-02-17 Thread Thomas Deutschmann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2017-02-16 23:56, Benny Pedersen wrote: > Tom Eastep skrev den 2017-02-16 23:29: > >> I sounds like it is Gentoo-specific, in which case I can't help >> you. We at shorewall.net do not release any Gentoo-specific init >> scripts or .service files

Re: [Shorewall-users] Accounting problem - am I missing something simple ?

2017-02-17 Thread Simon Hobson
Tom Eastep wrote: > -BEGIN PGP SIGNED MESSAGE- >> The diagram is useful, but doesn't show where accounting rules fit >> into it. > > It actually does. With ACCOUNTING_TABLE=mangle, all rules are in the > mangle table. When you section the accounting file, the rules in each > section are