Re: [Shorewall-users] shorewall with rocky 9

2024-02-14 Thread rcortes
Hi! is a simple scenario with 2 NIC, WAN and LAN. LAN-> WAN with full access same config with shorewall 5.1 dont work with 5.2 snat file contain: MASQUERADE 192.168.1.0/24 enp32s0f0 shorewall.conf change startup=YES some command to try debug why work with 5.1 but same

Re: [Shorewall-users] shorewall with rocky 9

2024-02-14 Thread Rodrigo Araujo
Hi. If you are migrating between versions, make a backup of the configuration and do a "shorewall upgrade" before starting shorewall. Ensure firewalld is stopped and disabled (this is important, or else "pure" nftable rules it generates will take precedence). Also make sure that the interfa

Re: [Shorewall-users] shorewall with rocky 9

2024-02-14 Thread Nigel Aves
I had a similar issue with Debian 12 ,,, Discovered this works in the snat file: MASQUERADE enp38s0 enp36s0 Might be worth a try. Nigel. On Wed, Feb 14, 2024 at 3:22 AM wrote: > Hi! > > is a simple scenario with 2 NIC, WAN and LAN. > > LAN-> WAN with full access > > same config with shorewall

Re: [Shorewall-users] shorewall with rocky 9

2024-02-14 Thread Tuomo Soini
On Wed, 14 Feb 2024 06:35:02 -0700 Nigel Aves wrote: > I had a similar issue with Debian 12 ,,, Discovered this works in the > snat file: > > MASQUERADE enp38s0 enp36s0 This is not correct syntax. Like man page shorewall-snat says: #ACTIONSOURCE DEST MASQUERADE 192.168.0.0/24

Re: [Shorewall-users] shorewall with rocky 9

2024-02-14 Thread Nigel Aves
All I'm doing is saying how it works on my server. On Wed, Feb 14, 2024 at 7:05 AM Tuomo Soini wrote: > On Wed, 14 Feb 2024 06:35:02 -0700 > Nigel Aves wrote: > > > I had a similar issue with Debian 12 ,,, Discovered this works in the > > snat file: > > > > MASQUERADE enp38s0 enp36s0 > > This i