Re: [Shorewall-users] SIP messaging - Masquarading troubles

2015-05-16 Thread Eric Koome
Not sure I understand. More specific what rules should I have to direct packets from proxy sent from its public ip directed to other asterisk box's rfc 1918 private address? >From ngrep this is what I see. Options packet: Box 1 178.89.67.12:5060 > Box 2 10.131.45.56 :5060 This

Re: [Shorewall-users] SIP messaging - Masquarading troubles

2015-05-14 Thread Eric Koome
packets in iptables? Sort of a trace? > On 14 May 2015, at 23:44, Lee Brown wrote: > >> On Thu, May 14, 2015 at 3:28 PM, Eric Koome wrote: >> Hi all, >> >> I have two servers with public and private IP address running a sip proxy on >> eth0 and asterisk box

[Shorewall-users] SIP messaging - Masquarading troubles

2015-05-14 Thread Eric Koome
Hi all, I have two servers with public and private IP address running a sip proxy on eth0 and asterisk box on eth1. Each box is running Shorewall 4.5.21. Making calls within a server is fine but I would like the sip proxy to also use asterisk box on the other machine for load balancing. Howeve

Re: [Shorewall-users] Shorewall Events - Port knock & DNAT

2014-06-07 Thread Eric Koome
ORT(S) DEST DNAT- net 192.168.1.5 tcp 22 - 206.124.146.178 SSHKnock net $FW tcp 1599,1600,1601 SSHKnock net loc:192.168.1.5 tcp 22 - 206.124.146.178 > On 8 Jun 2014, at 00:23, Tom Eastep wrote: > >> On 6/7/2014 4:04 PM, Eric Koome wrote: >> Hi all, >> >> I'm t

[Shorewall-users] Shorewall Events - Port knock & DNAT

2014-06-07 Thread Eric Koome
Hi all, I'm trying to implement port knocking for SSH behind NAT using Shorewall Events based on http://shorewall.net/Events.html, but no joy. The port seems to be always open. That is use of nmap to knock has no effect. DNAT net $FW:pri.va.te.ip tcp 22