Re: [Shorewall-users] block all IP addresses originating from the country of India

2015-01-22 Thread Orlandinei Vujanski
,smtps,submission > > > Bill > > On 1/22/2015 12:45 PM, Orlandinei Vujanski wrote: > > Good afternoon! > > I need help. > > I have to block all IP addresses originating from the country of India. > > I already know the networks, are approximately 500 networks. > >

Re: [Shorewall-users] block all IP addresses originating from the country of India

2015-01-22 Thread Orlandinei Vujanski
Thank you. 2015-01-22 16:06 GMT-02:00 PGNd : > > > > On 1/22/2015 12:45 PM, Orlandinei Vujanski wrote: > > > How could I make the networks stay in a separate file by country? > > > On Thu, Jan 22, 2015, at 09:54 AM, Bill Shirley wrote: > > Have yo

[Shorewall-users] block all IP addresses originating from the country of India

2015-01-22 Thread Orlandinei Vujanski
Good afternoon! I need help. I have to block all IP addresses originating from the country of India. I already know the networks, are approximately 500 networks. If I put each of the networks in the / etc / shorewall / rules, will be very large and confusing. How could I make the networks stay in a

[Shorewall-users] error - The firewall will not be started / stopped the unless it is configured

2014-10-22 Thread Orlandinei Vujanski
People, good morning. Could you help me? I installed Debian after Jessie and configure shorewall is giving the error below. Already do not know what to do. Thank you oot @ EMPVL0114254: / etc / shorewall # systemctl status shorewall.service ● shorewall.service - LSB: Configure the firewall at bo

Re: [Shorewall-users] 2 ISP + 2 LAN

2014-03-15 Thread Orlandinei Vujanski
Tom, is attached the dump 2014-03-15 15:59 GMT-03:00 Orlandinei Vujanski : > Tom, is attached the dump. > > > > > > > 2014-03-15 15:06 GMT-03:00 Tom Eastep : > >> In your masq file, you need: >> >> >> >> eth0 10.1.0.0/20 >> >>

Re: [Shorewall-users] 2 ISP + 2 LAN

2014-03-15 Thread Orlandinei Vujanski
I also had placed this item in the archive mask, still did not work. Any other suggestion Tom? 2014-03-15 14:22 GMT-03:00 Orlandinei Vujanski : > Tom, can you help me? > My network "eth1" 10.1.0.0/20 has to leave the default gateway "eth0" > 177.135.78.241. > M

Re: [Shorewall-users] 2 ISP + 2 LAN

2014-03-15 Thread Orlandinei Vujanski
w do I please! 2014-02-24 13:04 GMT-03:00 Tom Eastep : > On 2/24/2014 7:29 AM, Orlandinei Vujanski wrote: > > > 2014-02-23 12:52 GMT-03:00 Tom Eastep > <mailto:teas...@shorewall.net>>: > > > > On 2/23/2014 6:44 AM, Orlandinei Vujanski wrote: &

Re: [Shorewall-users] 2 ISP + 2 LAN

2014-02-24 Thread Orlandinei Vujanski
Tom, good morning. >From what I understand, I also need to configure the correct file /etc/shorewall/providers? Then I can work with virtual interface eth0:1 or must be physically? 2014-02-23 12:52 GMT-03:00 Tom Eastep : > On 2/23/2014 6:44 AM, Orlandinei Vujanski wrote: > > T

[Shorewall-users] 2 ISP + 2 LAN

2014-02-23 Thread Orlandinei Vujanski
Tom, Good afternoon, all right? Can you help me? I have 2 ISP link on my firewall, with the gateway: eth0: 177.135.78.1 eth1: 10.0.0.1 I also have 2 local network, being: eth2: 192.168.16.0/24 eth3: 10.1.0.0/20 How do I do so that the network 192.168.16.0/24 177.135.78.1 and exit through the Int

Re: [Shorewall-users] QoS - Shorewall

2013-12-05 Thread Orlandinei Vujanski
Em quinta-feira, 5 de dezembro de 2013, Emiliano Vazquez escreveu: > El 04/12/13 12:59, Orlandinei Vujanski escribió: > > good afternoon! > I can do that via shorewall any request from the 192.168.0.0/24 network > to network 10.3.0.0/24 occupy a maximum of 2mbps link? > >

[Shorewall-users] QoS

2013-12-04 Thread Orlandinei Vujanski
Tom, good afternoon! I am configuring QoS, but this error in generating tcdevices and tcclasses files as below: Dec 4 15:03:58 Compiling / etc / shorewall / tcclasses ... Dec 4 15:03:58 ERROR: Unknown INTERFACE (eth0) / etc / shorewall / tcclasses (line 2) Dec 4 15:10:04 Compiling / etc / shore

[Shorewall-users] QoS - Shorewall

2013-12-04 Thread Orlandinei Vujanski
good afternoon! I can do that via shorewall any request from the 192.168.0.0/24 network to network 10.3.0.0/24 occupy a maximum of 2mbps link? thank you -- Sponsored by Intel(R) XDK Develop, test and display web and hybri

[Shorewall-users] Problem SIP

2013-09-30 Thread Orlandinei Vujanski
Good afternoon Tom, okay? See if you can help me ... I have some users that connect via Softphone (SIP) outside my network. I've done a DNAT rule correctly. When these users connect, they can hear, but the other side can not hear. My telephony server receives connections by an alias eth0: 4 which i

Re: [Shorewall-users] RES: IPSEC - Please

2011-11-16 Thread Orlandinei Vujanski
Tom, good morning! Most of my network has a dedicated link with valid IP address on the network interface directly. And when the ADSL networks with the network to make IPSEC work? thank you 2011/11/15 Tom Eastep > > On Nov 15, 2011, at 3:43 PM, Orlandinei Vujanski wrote: > >

[Shorewall-users] RES: IPSEC - Please

2011-11-15 Thread Orlandinei Vujanski
: segunda-feira, 14 de novembro de 2011 09:37 Para: shorewall-users@lists.sourceforge.net Assunto: Re: [Shorewall-users] IPSEC - Please On Mon, 14 Nov 2011 08:21:16 -0200 Orlandinei Vujanski wrote: > Good morning!! > Which files have to configure an IPSec tunnel that can be > establis

[Shorewall-users] IPSEC - Please

2011-11-14 Thread Orlandinei Vujanski
Good morning!! Which files have to configure an IPSec tunnel that can be established? What documents can I follow the example? thank you -- RSA(R) Conference 2012 Save $700 by Nov 18 Register now http://p.sf.net/sfu/rsa-sf

[Shorewall-users] reports of logs shorewall

2010-12-04 Thread Orlandinei Vujanski
Good Afternoon, There are software to generate reports of the shorewall logs? If possible via Webmin? thanks -- What happens now with your Lotus Notes apps - do you make another costly upgrade, or settle for being maroone

Re: [Shorewall-users] Help

2010-12-01 Thread Orlandinei Vujanski
Do not want to remove Shorewall Tom, I want to pass these commands iptables shorewall, how? 2010/12/1 Tom Eastep > On 12/1/10 10:55 AM, Orlandinei Vujanski wrote: > > How to put the following rules in shorewall? > > > > iptables -I INPUT -d 172.25.5.192/28 <http://17

[Shorewall-users] Help

2010-12-01 Thread Orlandinei Vujanski
How to put the following rules in shorewall? iptables -I INPUT -d 172.25.5.192/28 -j ACCEPT iptables -I OUTPUT -d 172.25.5.192/28 -j ACCEPT iptables -I FORWARD -d 172.25.5.192/28 -j ACCEPT iptables -I INPUT -s 172.25.5.192/28 -j ACCEPT iptables -I OUTPUT -s 172.25.5.192/28 -j ACCEPT iptable

Re: [Shorewall-users] Problem FORWARD VPN IPSEC

2010-12-01 Thread Orlandinei Vujanski
Not thinking about ipsec, but only in error. How can I resolve this error FORWARD local network to the Internet? Thanks 2010/12/1 Tom Eastep > On 12/1/10 9:32 AM, Orlandinei Vujanski wrote: > > Good afternoon Tom, > > I have problems to release an IPSEC VPN. > > Thi

[Shorewall-users] Problem FORWARD VPN IPSEC

2010-12-01 Thread Orlandinei Vujanski
Good afternoon Tom, I have problems to release an IPSEC VPN. This generates the error below, how to resolve? eth0 = loc eth2 = net *Shorewall:FORWARD:DROP:IN=eth0 OUT=eth2 SRC=172.25.1.193 DST=200.228.200.90 * Thanks -

[Shorewall-users] Error - resolved.

2010-06-07 Thread Orlandinei Vujanski
resolved. /etc/shorewall/masq There is a long tradition of specifying an interface name in the SOURCE column of this file. Masquerading/SNAT occurs in the Netfilter POSTROUTING chain where an incoming interface may not be specified in iptables rules. Consequently, while processing the *shorewal

[Shorewall-users] Error

2010-06-07 Thread Orlandinei Vujanski
Know me know why the error? [Root @ CONLNX01 ~] # / etc / init.d / shorewall restart Compiling ... WARNING: Using an interface to the masq SOURCE Requires the interface to Be u When p and configured Shorewall starts / restarts / etc / shorewall / masq (line 3) Shorewall configuration compiled t

[Shorewall-users] RES: how do shorewall?

2010-06-03 Thread Orlandinei Vujanski
Thanks. -Mensagem original- De: Tom Eastep [mailto:teas...@shorewall.net] Enviada em: quinta-feira, 3 de junho de 2010 20:15 Para: shorewall-users@lists.sourceforge.net Assunto: Re: [Shorewall-users] how do shorewall? On 6/3/10 11:42 AM, Orlandinei Vujanski wrote: > Please how

[Shorewall-users] how do shorewall?

2010-06-03 Thread Orlandinei Vujanski
Please how do shorewall? -A PREROUTING -s 189.38.16.66 -d 187.50.185.60 -p tcp -m tcp --dport 3389 -j DNAT --to-destination 10.100.1.2 -A POSTROUTING -s 10.100.0.0/255.255.0.0 -d 10.100.1.7 -p tcp -m tcp --dport 53 -j SNAT --to-source 10.100.1.254 -A POSTROUTING -s 10.100.0.0/255.255.0.0 -o eth0

Re: [Shorewall-users] Problem release that does not work

2010-05-14 Thread Orlandinei Vujanski
thanks. I still have problem even after formatting the server. 2010/5/13 Tom Eastep > On 5/13/10 8:08 AM, Tom Eastep wrote: > > On 5/13/10 7:57 AM, Orlandinei Vujanski wrote: > >> Anex. > >> > >> > > > > Shorewall is not started. If you c

Re: [Shorewall-users] Problem release that does not work

2010-05-13 Thread Orlandinei Vujanski
Anex. Thanks Tom. 2010/5/12 Tom Eastep > On 5/12/10 2:47 PM, Orlandinei Vujanski wrote: > > Tom, all right? > > > > Until yesterday my shorewall was working perfectly, but today it stopped > > working. I already restarted the server, already changed the rules and &

[Shorewall-users] Redirection without FTP proxy

2010-05-03 Thread Orlandinei Vujanski
Good morning. How can I make requests in squid proxy on port 21 (FTP) does not pass through the proxy? Thanks -- ___ Shorewall-users mailing list Shorewall-users@lists.sourcefor

Re: [Shorewall-users] Help - Please

2010-04-28 Thread Orlandinei Vujanski
Thanks Tom This works perfectly. Congratulations. *Orlandinei Vujanski* Information Technology - Network Administrator Porto de Cima Adm. Part. e Serv. S/A - Grupo J.Malucelli (41) 3351-5587 www.jmalucelli.com.br <http://www.jmalucelli.com.br%20/> Esta mensagem pode conter info

Re: [Shorewall-users] Help - Please

2010-04-27 Thread Orlandinei Vujanski
Thanks Tom But my internal equipment only responds on port 2180, how do they respond to this request? 2010/4/27 Tom Eastep > On 04/27/2010 09:34 AM, Orlandinei Vujanski wrote: > > How do in Shorewall? > > > > > > iptables -t nat -A PREROUTING-d 200.200.10.10 -p t

[Shorewall-users] Help - Please

2010-04-27 Thread Orlandinei Vujanski
How do in Shorewall? iptables -t nat -A PREROUTING-d 200.200.10.10 -p tcp - dport 2181 -j DNAT - to 10.101.71: 2180 iptables -A FORWARD -d 10.101.7.1 -p tcp -dport 2180 - syn -j ACCEPT Thanks --

Re: [Shorewall-users] Problem Shorewall

2010-01-27 Thread Orlandinei Vujanski
I thought DNAT rules was also required to pass the port and protocol. I will test tomorrow. Thank Tom. 2010/1/27 Tom Eastep > Orlandinei Vujanski wrote: > > Sorry. > > I need to make all Internet requests on IP 172.25.5.1 is redirected to > > the IP 10.120.7.1 port in

Re: [Shorewall-users] Problem Shorewall

2010-01-27 Thread Orlandinei Vujanski
Sorry. I need to make all Internet requests on IP 172.25.5.1 is redirected to the IP 10.120.7.1 port indifferent. How do the shorewall? Sorry for my bad english. Desculpe. Preciso fazer com que todas as solicitações da Internet no IP 172.25.5.1 sejam redirecionados para o IP 10.120.7.1 indiferen

[Shorewall-users] Problem Shorewall

2010-01-27 Thread Orlandinei Vujanski
-- The Planet: dedicated and managed hosting, cloud storage, colocation Stay online with enterprise data centers and the best network in the business Choose flexible plans and management services without long-term contract