Re: [Shorewall-users] Problem accesing from outside

2017-10-27 Thread Rommel Rodriguez Toirac
El oct. 26, 2017 7:10 PM, Bill Shirley escribió:You don't have any name servers for gob.cu: ; <<>> DiG 9.10.3-P4-RedHat-9.10.3-9.P4.fc22 <<>> gob.cu ns ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1071 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY

Re: [Shorewall-users] Disobeying Settings to Allow SMTP

2017-10-27 Thread cacook
>> I'm getting: >> >> # dmesg >> [181685.067416] Shorewall:fw-net:ACCEPT:IN= OUT=eth0 SRC=72.251.231.102 >> DST=199.127.58.3 LEN=48 TOS=0x00 PREC=0x00 TTL=64 ID=53282 DF PROTO=TCP >> SPT=17554 DPT=25 WINDOW=29200 RES=0x00 SYN URGP=0 UID=89 GID=89 > That looks like it's passing the traffic to me

Re: [Shorewall-users] Disobeying Settings to Allow SMTP

2017-10-27 Thread PGNet Dev
On 10/27/17 8:48 AM, cac...@quantum-sci.com wrote: In fact half the time, REJECTs and DROPs are -not- logged, and I have to figure out why without the aid of informational messages. Shorewall does a great job of doing exactly what it's told to do. If "half the time, REJECTs and DROPs are -not-

Re: [Shorewall-users] Disobeying Settings to Allow SMTP

2017-10-27 Thread cacook
On 10/27/2017 09:24 AM, PGNet Dev wrote: > On 10/27/17 8:48 AM, cac...@quantum-sci.com wrote: >> In fact half the time, REJECTs and DROPs are -not- logged, and I have >> to figure out why without the aid of informational messages. > > Shorewall does a great job of doing exactly what it's told to do

Re: [Shorewall-users] Disobeying Settings to Allow SMTP

2017-10-27 Thread Tom Eastep
On 10/27/2017 09:42 AM, cac...@quantum-sci.com wrote: > On 10/27/2017 09:24 AM, PGNet Dev wrote: >> On 10/27/17 8:48 AM, cac...@quantum-sci.com wrote: >>> In fact half the time, REJECTs and DROPs are -not- logged, and I have >>> to figure out why without the aid of informational messages. >> >> Sho

Re: [Shorewall-users] Disobeying Settings to Allow SMTP

2017-10-27 Thread cacook
> Well, so far, all you have given us is a log message, one rule, and a > "It works sometimes". > > Given that the rule you posted doesn't include a log level, but a log > message is being produced, I am wondering if the fw->net policy is > ACCEPT with a log level specified. If that is the case, t

Re: [Shorewall-users] Disobeying Settings to Allow SMTP

2017-10-27 Thread cacook
On 10/27/2017 10:27 AM, cac...@quantum-sci.com wrote: > >> Well, so far, all you have given us is a log message, one rule, and a >> "It works sometimes". >> >> Given that the rule you posted doesn't include a log level, but a log >> message is being produced, I am wondering if the fw->net policy i

Re: [Shorewall-users] Disobeying Settings to Allow SMTP

2017-10-27 Thread Simon Hobson
cac...@quantum-sci.com wrote: > Eh, except I got bounced with: > > SMTP error from remote mail server after RCPT TO: > : > 504 5.5.2 : Helo command rejected: need fully-qualified hostname You would sending mail direct to me as well - your mail server is not correctly configured ! Your mail

Re: [Shorewall-users] Disobeying Settings to Allow SMTP

2017-10-27 Thread Simon Hobson
cac...@quantum-sci.com wrote: > Eh, except I got bounced with: > > SMTP error from remote mail server after RCPT TO: > : >504 5.5.2 : Helo command rejected: need fully-qualified hostname You would have the same problem sending mail direct to me as well - your mail server is not correctly co

Re: [Shorewall-users] Disobeying Settings to Allow SMTP

2017-10-27 Thread cacook
On 10/27/2017 10:56 AM, Simon Hobson wrote: > cac...@quantum-sci.com wrote: > >> Eh, except I got bounced with: >> >> SMTP error from remote mail server after RCPT TO: >> : >> 504 5.5.2 : Helo command rejected: need fully-qualified hostname > You would sending mail direct to me as well - your m

Re: [Shorewall-users] Disobeying Settings to Allow SMTP

2017-10-27 Thread Tom Eastep
On 10/27/2017 10:40 AM, cac...@quantum-sci.com wrote: > On 10/27/2017 10:27 AM, cac...@quantum-sci.com wrote: > >> >>> Well, so far, all you have given us is a log message, one rule, and a >>> "It works sometimes". >>> >>> Given that the rule you posted doesn't include a log level, but a log >>> m

Re: [Shorewall-users] Problem accesing from outside

2017-10-27 Thread Rommel Rodriguez Toirac
Hello all; here I send some configs and traces of my shorewall firewall.I have been made some workaround, so maybe this is a little diferent to the one that I send in the shorewall-dump.tar.gz; but still the problem is present.This are the situation. Our networks are private.(municipals network use