Re: [Shorewall-users] Shorewall Disobeying rules?

2020-08-05 Thread colony.three--- via Shorewall-users
I see. Chrony is getting blocked. All this setup is temporary because soon it will be going through a WireGuard tunnel. ‐‐‐ Original Message ‐‐‐ On Wednesday, August 5, 2020 10:51 AM, Tom Eastep wrote: > On 8/5/20 10:30 AM, colony.three--- via Shorewall-users wrote: > > > HAZZAH,

Re: [Shorewall-users] Shorewall Disobeying rules?

2020-08-05 Thread Tom Eastep
On 8/5/20 9:30 AM, colony.three--- via Shorewall-users wrote: > Thank you Tom, but actually there is a DNS ACCEPT rule. > > I didn't make this clear enough but I am trying to dnat from net to local, > for example incoming port 51554 to local 10.2.20.51:554 . Here are my rules: > > # Cameras >

Re: [Shorewall-users] Shorewall Disobeying rules?

2020-08-05 Thread Tom Eastep
On 8/5/20 10:30 AM, colony.three--- via Shorewall-users wrote: > HAZZAH, like magic the Master does it again! > > This is regular Shorewall, compiling rules in its own machine, all in > /etc/shorewall. > > BUT, AUTOMAKE=Yes. As soon as I set it to No, everything started TWERKING! > > Thank

Re: [Shorewall-users] Shorewall Disobeying rules?

2020-08-05 Thread colony.three--- via Shorewall-users
HAZZAH, like magic the Master does it again! This is regular Shorewall, compiling rules in its own machine, all in /etc/shorewall. BUT, AUTOMAKE=Yes. As soon as I set it to No, everything started TWERKING! Thank you again Tom. I never would have found this in a million years. For others,

Re: [Shorewall-users] Shorewall Disobeying rules?

2020-08-05 Thread Tom Eastep
On 8/5/20 9:30 AM, colony.three--- via Shorewall-users wrote: > Thank you Tom, but actually there is a DNS ACCEPT rule. > > I didn't make this clear enough but I am trying to dnat from net to local, > for example incoming port 51554 to local 10.2.20.51:554 . Here are my rules: > > # Cameras >

Re: [Shorewall-users] Shorewall Disobeying rules?

2020-08-05 Thread colony.three--- via Shorewall-users
Thank you Tom, but actually there is a DNS ACCEPT rule. I didn't make this clear enough but I am trying to dnat from net to local, for example incoming port 51554 to local 10.2.20.51:554 . Here are my rules: # Cameras ACCEPT net:10.2.1.4$FW tcp 50554 - DNAT

Re: [Shorewall-users] Shorewall Disobeying rules?

2020-08-05 Thread colony.three--- via Shorewall-users
Hi Matt, local (cameras) zone is 10.2.20.1 and net zone is 10.2.1.106. If I do shorewall clear, dnat can't work. I didn't try to access http/https during that snip. ‐‐‐ Original Message ‐‐‐ On Wednesday, August 5, 2020 9:01 AM, Matt Darfeuille wrote: > On 8/5/2020 5:03 PM,

Re: [Shorewall-users] Shorewall Disobeying rules?

2020-08-05 Thread Tom Eastep
On 8/5/20 8:03 AM, colony.three--- via Shorewall-users wrote: > I have struggled for days to make this work but admit I am soundly defeated. > > My goal is to dnat two cameras through an Odroid N2+.  But I can't even > get a basic ACCEPT to work on ports 80 or 443.  I can't understand what > is

Re: [Shorewall-users] Shorewall Disobeying rules?

2020-08-05 Thread Matt Darfeuille
On 8/5/2020 5:03 PM, colony.three--- via Shorewall-users wrote: > I have struggled for days to make this work but admit I am soundly defeated. > > My goal is to dnat two cameras through an Odroid N2+. But I can't even get a > basic ACCEPT to work on ports 80 or 443. I can't understand what is

[Shorewall-users] Shorewall Disobeying rules?

2020-08-05 Thread colony.three--- via Shorewall-users
I have struggled for days to make this work but admit I am soundly defeated. My goal is to dnat two cameras through an Odroid N2+. But I can't even get a basic ACCEPT to work on ports 80 or 443. I can't understand what is wrong. Dump is attached. Sure hope the boss is still around. [Tue Jan 30