[Shorewall-users] redirect only for parent zone, excluding ipset

2022-02-16 Thread Kevin Olbrich via Shorewall-users
Hi! I have to set up a captive portal login for a public network which works fine so far. The access points use the same network, the clients use. I have these main zones: - net -> upstream - clt -> untrusted clients - cpalw -> captive portal allowed users, child zone of clt - white -> whitelist

Re: [Shorewall-users] Shared config mode (sw/sw6) and rules file, ipv4 /ipv6

2020-03-18 Thread Kevin Olbrich
Thank you Tom! Am Mi., 18. März 2020 um 18:07 Uhr schrieb Tom Eastep : > > On 3/18/2020 3:28 AM, Kevin Olbrich wrote: > > Hi! > > > > I've noticed an issue with shorewall6 in shared mode. > > My ipv4 firewall is working fine: > > > > rules: &g

[Shorewall-users] Shared config mode (sw/sw6) and rules file, ipv4 /ipv6

2020-03-18 Thread Kevin Olbrich
Hi! I've noticed an issue with shorewall6 in shared mode. My ipv4 firewall is working fine: rules: ACCEPT all:9.9.9.9 fw udp 161 shorewall6 complains: ERROR: Unknown Host (9.9.9.9) /etc/shorewall/rules (line 62) Obvious what happens here but do I need to wrap all my v4 r

Re: [Shorewall-users] Disabling all helpers

2019-02-06 Thread Kevin Olbrich
Am Mi., 6. Feb. 2019 um 21:06 Uhr schrieb Tom Eastep : > > On 2/6/19 11:57 AM, Kevin Olbrich wrote: > > Hi Tom, > > > > this system only hosts asterisk, nothing else. > > It seems I don't need any helper, just normal conntrack for outgoing > &

Re: [Shorewall-users] Disabling all helpers

2019-02-06 Thread Kevin Olbrich
Am Mi., 6. Feb. 2019 um 19:15 Uhr schrieb Sassy Natan : > > hi, > > can u send the lsmod ouput? > > > > On Wed, Feb 6, 2019 at 7:52 PM Kevin Olbrich wrote: >> >> Hi! >> >> I read this article: >> http://shorewall.org/Helpers.html >> >

Re: [Shorewall-users] Disabling all helpers

2019-02-06 Thread Kevin Olbrich
i., 6. Feb. 2019 um 19:44 Uhr schrieb Tom Eastep : > > On 2/6/19 10:13 AM, Tom Eastep wrote: > > On 2/6/19 9:50 AM, Kevin Olbrich wrote: > >> Hi! > >> > >> I read this article: > >> http://shorewall.org/Helpers.html > >> > >> Currently I

[Shorewall-users] Disabling all helpers

2019-02-06 Thread Kevin Olbrich
Hi! I read this article: http://shorewall.org/Helpers.html Currently I have some problems with an Asterisk installation and broken SIP packets (because they are generated by bots). While I try to debug this, I noticed that the SIP helper is active. As far as I understand, I don't need it because

[Shorewall-users] A big thank you!

2019-01-25 Thread Kevin Olbrich
Hi! I want to say thank you to all involved in the project (development, debug, etc.)! Especially Tom, who seems to work a lot on Shorewall to make it even better with each update. Many projects that I lead use shorewall, routers as well as servers (must be about thousand?). It is stable, reliabl

Re: [Shorewall-users] stoppedrules examples potentially unsafe with IPv6?

2018-11-24 Thread Kevin Olbrich
Hi! Actually I think this behaviour is correct. IPv6 is meant to be routet global by default, thats what was in mind when it was invented. Sure, it would be better to display a warning in the docs. Most firewalls route traffic of internal interfaces (some kind of trusted zones) while there is one

Re: [Shorewall-users] SECTIONS in shorewall-rules

2018-11-05 Thread Kevin Olbrich
5:26 Uhr schrieb Justin Pryzby < pry...@telsasoft.com>: > > On Thu, Nov 01, 2018 at 02:07:44PM +0100, Kevin Olbrich wrote: > > Hi! > > > > I have these rules in my shorewall-rules: > > > > > # Allow ping to the callserver > > > Ping(ACCEPT) all

[Shorewall-users] SECTIONS in shorewall-rules

2018-11-01 Thread Kevin Olbrich
Hi! I have these rules in my shorewall-rules: > # Allow ping to the callserver > Ping(ACCEPT) all fw > # Allow SSH to the callserver > ACCEPT all fw tcp 1337 > # Allow SIP traffic to the callserver from the internet > ACCEPT net fw udp 5060 > ACCEPT net fw tcp 5060 > ACCEPT net fw tcp 5061 I ne

Re: [Shorewall-users] Missing packages

2018-09-20 Thread Kevin Olbrich
Hi! Are you sure you have universe repository enabled? https://packages.ubuntu.com/bionic/shorewall Mit freundlichen Grüßen / best regards, Kevin Olbrich. Am Do., 20. Sep. 2018 um 14:52 Uhr schrieb Eric Teeter : > I guess that this is more of a rhetorical question. Does anyone know

Re: [Shorewall-users] Block outgoing routing of martians via default GW

2018-08-08 Thread Kevin Olbrich
Works perfectly! Thank you very much! Kevin Am Di., 7. Aug. 2018 um 16:55 Uhr schrieb Tom Eastep : > On 08/07/2018 02:48 AM, Kevin Olbrich wrote: > > Hi! > > > > On a single node server with local shorewall, packets are routed outside > > (public network) which co

[Shorewall-users] Block outgoing routing of martians via default GW

2018-08-07 Thread Kevin Olbrich
Hi! On a single node server with local shorewall, packets are routed outside (public network) which contain private addresses not known locally. Is it possible to drop private network packets on the public interface from going out? Kevin ---