Re: [Shorewall-users] The end of the road...

2019-02-21 Thread Răzvan Sandu
Hello aa, From Bucharest, Romania, I just want to intervene here to say a BIG THANK YOU to Tom and all other Shorewall developers! As for the future solution for (easier) firewalls, maybe the firewalld package (which is already the standard in the Red Hat-based distros, even if it lacks all Shore

[Shorewall-users] Please help on shorewall-rules syntax

2018-06-21 Thread Răzvan Sandu
Hello Tom, hello all, Please help me a little bit about the correct syntax of a shorewall rule (in shorewall-rules file). I now have: IMAPS/ACCEPT:info net $FW and I want to exclude *two* adddress ranges from the net zone, like in: IMAPS/ACCEPT:info net:!aa.bb.cc.0/24 $FW But

Re: [Shorewall-users] Please include macros for ipfs in Shorewall

2018-04-20 Thread Răzvan Sandu
Hello, Following Tom's kind advice, here are the three macros needed for ipfs. Please include them in distro. # # Shorewall -- /usr/share/shorewall/macro.IPFS-swarm # # This macro handles IPFS data traffic (the connection to IPFS swarm). #

[Shorewall-users] Please include macros for ipfs in Shorewall

2018-04-13 Thread Răzvan Sandu
Hello, ipfs (please see https://ipfs.io/) is a very useful peer-to-peer protocol that attempts to become the next-generation Web (HTTP2). It is rapidly gaining momentum. An ipfs node (there is no "server" or "client", each node acts as both) uses by default the following three ports to communica

[Shorewall-users] iptables and iptables-services RPM dependencies

2017-02-23 Thread Răzvan Sandu
Hello, FYI, the Red Hat/Fedora lists discuss removing the dependency between the "iptables" and "iptables-services" RPM packages. This will affect shorewall and shorewall6. Please see bugs: https://bugzilla.redhat.com/show_bug.cgi?id=1327786 https://bugzilla.redhat.com/show_bug.cgi?id=1424954

[Shorewall-users] A FAQ: Please explain how to define and use VLAN interfaces

2016-06-13 Thread Răzvan Sandu
Hello, Please explain (in a piece of documentation similar to http://shorewall.net/Shorewall_and_Aliased_Interfaces.html) how to *correctly* define and use VLAN interfaces with shorewall. This seems to be an entirely different situation than aliased interfaces, because of their (desired) complete

Re: [Shorewall-users] [RFE] Please include tinc macro in stock shorewall package

2015-09-19 Thread Răzvan Sandu
Tom Eastep wrote: I'll replace your previously-submitted macro with this one. Hello, Thanks a lot for your quick reaction and for shorewall itself, that is a *great* tool! The main differences between the two macros are: 1. the "?FORMAT 2" line and 2. I've added the TCP protocol on port

[Shorewall-users] [RFE] Please include tinc macro in stock shorewall package

2015-09-17 Thread Răzvan Sandu
Hello, Please include tinc macro (macro.Tinc file) in stock shorewall package (under /usr/share/shorewall for IPv4 and the corresponding place for IPv6). Tinc (http://www.tinc-vpn.org/) is a popular VPN solution, similar to OpenVPN, but mesh-capable. It uses standard port 655 on both TCP and

Re: [Shorewall-users] Please add support for tinc VPN in Shorewall

2015-01-12 Thread Răzvan Sandu
Hello, Thank you for your kind answers. Please include the following macro for tinc in the future versions of shorewall (copy-paste), as /usr/share/shorewall/macro.tinc file, with appropriate permissions: # # Shorewall version 4 - tinc Macro # # /usr/share/shorewall/macro.tinc Macro # #

Re: [Shorewall-users] Please add support for tinc VPN in Shorewall

2014-12-12 Thread Răzvan Sandu
Thank you, On 11.12.2014 16:43, Eric Teeter wrote: I have summited a few macros myself, one macro.ActiveDir which is vary complicated. PARAM - - udp 655 PARAM - - tcp 655 I'll write a macro, with proper comments, ad I'll be happy to post it here, in ord

[Shorewall-users] Please add support for tinc VPN in Shorewall

2014-12-11 Thread Răzvan Sandu
Hello, Would you please help adding support for tinc VPN in shorewall? As stated in Fedora EPEL bug #1161116 (https://bugzilla.redhat.com/show_bug.cgi?id=1161116): Tinc (http://www.tinc-vpn.org/) is a popular, cross-distro VPN solution that allows MESH networks. For RedHat family, it is av