Re: [Shorewall-users] Security question around MySQL Replication

2017-09-11 Thread Dominic Benson
On 11/09/17 13:49, Phil Stracchino wrote: > On 09/11/17 07:29, Davide Marchi wrote: >> Hi friends, >> >> I've enabled between two servers (VPS Debian Jessie), the MySQL >> Replication feature. >> For this I've open the "3306" port. >> >> >> My question: is this a safe operation or should I also

Re: [Shorewall-users] Remapping port below 1024 on the firewall

2013-10-10 Thread Dominic Benson
On 10 Oct 2013, at 18:52, Brian Burch br...@pingtoo.com wrote: On 10/10/13 17:55, johnny bowen wrote: REDIRECTnet 22 tcp 902 Thanks for thinking about it Johnny, but I said in my first post that I couldn't make REDIRECT work in my situation. Isn't it

Re: [Shorewall-users] NAT/masq out of specific IP with multi-ISP

2013-09-05 Thread Dominic Benson
On 5 Sep 2013, at 22:40, Tracy Reed tr...@ultraviolet.org wrote: I've got a few bucks available for a really good Shorewall consultant since I haven't yet been able to figure this one out myself... On Tue, Sep 03, 2013 at 11:49:22AM PDT, Tracy Reed spake thusly: Hello all, I am running

Re: [Shorewall-users] Transparent Proxy

2013-05-08 Thread Dominic Benson
On 8 May 2013, at 05:45, cac...@quantum-sci.com wrote: On Tuesday, May 07, 2013 06:58:50 PM Terry Gilsenan wrote: Firstly, Is the mail client socks aware? If it is not then that is the issue you need to fix. If it is, then tell it to use the socks proxy on port 9110 Shorewall is an

Re: [Shorewall-users] SHOREWALL - ISP Y LOAD BALANCEā€

2011-09-01 Thread Dominic Benson
On 01/09/11 16:28, Tom Eastep wrote: On Thu, 2011-09-01 at 14:33 +, Geovana Navarro wrote: I think I explained wrong, my purpose is not to get 12 Mbps per link, I know that is not possible. Again I explain my problem, this will show the scheme of my academic project. I am working with

Re: [Shorewall-users] Tproxy with Shorewall6

2011-07-07 Thread Dominic Benson
On 7 Jul 2011, at 01:22, Tom Eastep wrote: On Jul 6, 2011, at 5:17 PM, J. Randall Owens wrote: I don't know about TPROXY in particular, but in most places in shorewall6, you can enclose the IPv6 addresses (including prefix length) in angle brackets, like so (all mine are in hosts so

Re: [Shorewall-users] Tproxy with Shorewall6

2011-07-07 Thread Dominic Benson
On 07/07/11 14:39, Tom Eastep wrote: On Thu, 2011-07-07 at 04:22 -0700, J. Randall Owens wrote: I take that back now. While it's not on that page, I see where Tc.pm has a place for picking out an IP address as a third parameter. In that case, I'd say that process_tc_rule is messing up at

Re: [Shorewall-users] DNAT behaves like DNAT-

2011-07-06 Thread Dominic Benson
On 6 Jul 2011, at 22:59, Alexander Wilms wrote: Ack, downgraded to plain openSUSE iptables-1.4.10-3.1.i586.rpm, result is now a correct ctorigdstport 52022 160 ACCEPT tcp -- * * 0.0.0.0/0192.168.1.2 tcp dpt:22 ctorigdstport 52022 ctorigdst

Re: [Shorewall-users] DNAT behaves like DNAT-

2011-07-06 Thread Dominic Benson
On 7 Jul 2011, at 00:09, Tom Eastep wrote: On Jul 6, 2011, at 3:26 PM, Dominic Benson wrote: On 6 Jul 2011, at 22:59, Alexander Wilms wrote: Ack, downgraded to plain openSUSE iptables-1.4.10-3.1.i586.rpm, result is now a correct ctorigdstport 52022 160 ACCEPT tcp

Re: [Shorewall-users] A can't Ping B until C has pinged A (ipv6)

2011-02-25 Thread Dominic Benson
On 25/02/11 11:04, shorewall shorewall wrote: I have two Debian 6 x64 VMs running under ESXi4.1_U1. One of the VMs is acting as an ipv4 and ipv6 firewall/router using shorewall and has three virtual NICs, LAN, WAN and DMZ. I've set up a 6in4 ipv6 tunnel from Hurricane Electric on the router

Re: [Shorewall-users] FAQ 2b ...

2011-02-24 Thread Dominic Benson
On 24 Feb 2011, at 19:37, Tom Eastep wrote: On 2/24/11 11:22 AM, Paolo Andretta wrote: Would something roughly as documented here: http://www.shorewall.net/FAQ.htm#faq2 help? As in the subject and in my explanation (my english is poor but hope unsterstandable), I read Faq 2 and

Re: [Shorewall-users] FAQ 2b ...

2011-02-23 Thread Dominic Benson
On 23/02/11 16:56, Paolo Andretta wrote: On Wed, 23 Feb 2011, Tom Eastep wrote: I have a server in my DMZ. I configured it with a DNAT rule and added the IP to the /etc/shorewall/masq so it is acccessible from the Internet and it is see with its public IP. No problem on this. If I try