Re: [Shorewall-users] some ICMPv6 messages don't make it through SNAT

2024-03-13 Thread Tuomo Soini
setup): > 0 6 - 13/Mar/2024:16:19:50 + Sh6:rplog:DROP:IN=AMS2 > SRC=2001:470:1:18::3:1280 DST=fdbf:1d37:bbe0:0:48::35 LEN=1240 TC=0 > FLOWLBL=0 HOPLIMIT=240 PROTO=ICMPV6 TYPE=2 CODE=0 MTU=1280 Note rplog here. That means rpfilter is preventing this packet. That means you have a probl

Re: [Shorewall-users] Fwd: some ICMPv6 messages don't make it through SNAT

2024-03-13 Thread Tuomo Soini
block packet too big icmpv6. So you can't reach any of their servers with IPv6 behind VPN. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mailing list Shorewall-users@

Re: [Shorewall-users] Strangeness with SANE macro - any ideas?

2024-03-01 Thread Tuomo Soini
TOHELPERS enabled any more. I suggest you switch to AUTOHELPERS=No and test again because you likely have later than 3.5 kernel. https://shorewall.org/Helpers.html#idm217 -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https

Re: [Shorewall-users] Can I ignore failing rules?

2024-02-28 Thread Tuomo Soini
don't have issues with startup failing if ipset is missing which was one issue we found with ipset based solution. https://github.com/FoobarOy/foomuuri/wiki/Configuration#resolve That's not shorewall but created by guys who used shorewall for 20 years. -- Tuomo Soini Foobar Linux services +358

Re: [Shorewall-users] Can I ignore failing rules?

2024-02-28 Thread Tuomo Soini
.exist.com tcp 443 I suggest you read this part of documentation before using dns names in your config. Especially the first Caution. https://shorewall.org/manpages/shorewall-names.html#idm30 -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy

Re: [Shorewall-users] shorewall with rocky 9

2024-02-14 Thread Tuomo Soini
2.168.0.0/24 eth0 So source must be a network, not an interface. Also note /etc/shoreall/masq is deprecated. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mailing li

Re: [Shorewall-users] shorewall with rocky 9

2024-02-13 Thread Tuomo Soini
nstalled. Other than that, I'm not > remembering anything. It also works very well with iptables-nft (so without iptables-legacy). -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mail

Re: [Shorewall-users] why do I have requests from inside apache server with source ports 80 and 443

2023-10-26 Thread Tuomo Soini
tocol name, so shorewall developers decided to add HTTP and HTTPS macros which are actual protocol names instead. But to make sure old firewall installs won't break on shorewall upgrade, old Web macro was left there. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foob

Re: [Shorewall-users] shorewall does not log any activity after system startup, but after a manual reload

2023-08-10 Thread Tuomo Soini
should be /var/log/syslog. Because shorewall does not itself do logging (kernel does) LOGFILE in shorewall.conf tells shorewall where from to find the log, not where to log. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___

Re: [Shorewall-users] [Announce] Foomuuri - New firewall software using nftables

2023-06-07 Thread Tuomo Soini
On Tue, 6 Jun 2023 09:51:05 -0400 Alex wrote: > On Wed, May 3, 2023 at 4:55 PM Tuomo Soini wrote: > > > Read the announcement message from netfilter mailinglist archive. > > > > https://marc.info/?l=netfilter=168198959919079=2 > > > Is there a mig

[Shorewall-users] [Announce] Foomuuri - New firewall software using nftables

2023-05-03 Thread Tuomo Soini
Read the announcement message from netfilter mailinglist archive. https://marc.info/?l=netfilter=168198959919079=2 -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mailing list Shorewall

Re: [Shorewall-users] Multi-Homed BGP - Shorewall & FRR

2023-04-27 Thread Tuomo Soini
to do any routing related stuff and especially NOT multi-isp. BGP4 routing is by definition asymmetric and managed by routing daemon. You also do not want to have default route on your system at all. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___

Re: [Shorewall-users] Redirect incoming connection on a given interface to the loopback interface

2023-04-12 Thread Tuomo Soini
ng and then this rule works just fine. > > I could not find a setting for this in shorewall.conf, but it's easy > enough to have it applied at every boot, so I'm fine. You can add that config to /etc/sysctl.d/50-local.conf for example. --

Re: [Shorewall-users] Redirect incoming connection on a given interface to the loopback interface

2023-04-05 Thread Tuomo Soini
0 TTL=128 ID=4850 DF > PROTO=TCP SPT=51232 DPT=1883 WINDOW=64240 RES=0x00 SYN URGP=0 REDIRECT does not change destination ip - you need to change your software to listen all ip addresses for redirect to work. DNAT is the way if you need to change destination ip. -- Tuomo Soini Foobar Linux s

Re: [Shorewall-users] ACK replies are dropped

2022-05-04 Thread Tuomo Soini
hout logging, if you don't want to see those packets, add dropInvalid to DROP_DEFAULT. It is that easy. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/shorewall-users

Re: [Shorewall-users] FTP SSL

2022-03-16 Thread Tuomo Soini
ee data port in command packet to open data connection and because TLS encrypts command channel conntrack module can't handle it. That is why FTP has always been horrible option for data transfers with firewalling. FTP is dead - move to SFTP which uses ssh protocol. -- Tuomo Soini Foobar Linux serv

Re: [Shorewall-users] Filtering on Ether type, not port

2022-03-02 Thread Tuomo Soini
well. I take from this your issue is pure logging of this access. I'd just drop that connection try without logging like this: HTTP(DROP) net: $FW -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/>

Re: [Shorewall-users] Shorewall dhcp query

2022-02-16 Thread Tuomo Soini
from inet zone, dhcp > interface is getting ipv4 address . > But for ipv6 the advertise packets(packets from dhcpv6 server) are > getting dropped by the firewall. Why is this happening? Any input > will be helpful. check /etc/shorewall6/interfaces for option dhcp -- Tuomo Soini Fo

Re: [Shorewall-users] Socket6::gethostbyname2 not implemented on this architecture

2022-02-13 Thread Tuomo Soini
On Sat, 12 Feb 2022 13:45:45 -0500 "Brian J. Murrell" wrote: > On Tue, 2022-02-08 at 10:36 +0200, Tuomo Soini wrote: > > > > I'll test the patch on rhel7 based system and we'll see if that > > works there - I don't think there is any older supported distro out

Re: [Shorewall-users] SSDP: Trying to allow responses through the firewall

2022-02-09 Thread Tuomo Soini
acket, not untracked. So alternive way would be to add this rule back but at this time to NEW section. > ACCEPT net:192.168.0.0/24 $FW udp - 1900 If you send packet to multicast address but you get response from unicast address, that is a new connection. -- Tuomo Soin

Re: [Shorewall-users] Socket6::gethostbyname2 not implemented on this architecture

2022-02-08 Thread Tuomo Soini
which is a good thing. I'll test the patch on rhel7 based system and we'll see if that works there - I don't think there is any older supported distro out there... -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> _

Re: [Shorewall-users] Shorewall6 start error

2021-12-09 Thread Tuomo Soini
16384 0 > nf_log_common 16384 2 nf_log_ipv4,nf_log_ipv6 > nf_defrag_ipv6 16384 1 nf_conntrack Are you compiling your own kernel? You sure do need nf_reject_ipv6. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> __

Re: [Shorewall-users] Shorewall6 start error

2021-12-09 Thread Tuomo Soini
an just do routing and don't need to do proxyndp. Giving single network would be violation of rfcs, everybody need proper IPv6 block from their isp, like /60 at minimum (16 networks) or /56 (256 networks). -- Tuomo Soini Foobar Linux services +358 40 5240030

Re: [Shorewall-users] Reach dmz host from within dmz zone with public ip address

2021-10-26 Thread Tuomo Soini
eal (not public) addresses in /etc/hosts on all servers so that packets won't go to firewall. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.ne

Re: [Shorewall-users] Help with routing

2021-09-13 Thread Tuomo Soini
routing, but it doesn't appear to have any ability to delete > unwanted routes. That means dedicated link must have ip address with netmask /32 and static host route to other machine. Other interface has normal config. It would be easier if you could use different network address for dedicat

Re: [Shorewall-users] Disabling logging into journal

2021-09-08 Thread Tuomo Soini
Unfortunately that is not possible because logging goes to journal and then rsyslog reads logs from journal to log files. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mailing list Shorewall-users@

Re: [Shorewall-users] Issues with default route

2021-07-27 Thread Tuomo Soini
eway from interface script, correct place to configure is in /etc/shorewall/providers -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/shorewall-users

Re: [Shorewall-users] Issues with default route

2021-07-26 Thread Tuomo Soini
ace. And with multi-isp you are always required to reload shorewall after operations to interface. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.

Re: [Shorewall-users] Shorewall 5.1.6 not recognizing eth0 after ubuntu upgrade

2021-07-09 Thread Tuomo Soini
used if you have it. If you have that script you should check what's in /var/lib/shorewall/eth0.status file... -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mailing list Shor

Re: [Shorewall-users] Shorewall 5.1.6 not recognizing eth0 after ubuntu upgrade

2021-07-09 Thread Tuomo Soini
On Fri, 9 Jul 2021 10:33:34 +0100 Norman and Audrey Henderson wrote: > HELP! > I have a system in the cloud that was running Ubuntu 16.04 and > ifupdown. One interface eth0 with two addresses, 0.38.15.82 and > 0.38.15.83/29. Network 0/8 is reserved and can not be used. -- Tuomo S

Re: [Shorewall-users] last missing Shorewall6 piece, ping6 from LAN to 'NET ?

2021-05-19 Thread Tuomo Soini
On Tue, 18 May 2021 17:57:32 -0400 tha...@letterboxes.org wrote: > Feels like I'm finally close to getting this all working at the same > time. I'm still missing the last piece -- ping6 from LAN to 'NET I'd guess you forgot to enable ipv6 forwarding. -- Tuomo Soini Foobar Linux service

Re: [Shorewall-users] IPv6 Routing issue

2021-04-06 Thread Tuomo Soini
ref medium 2601:681:4100:d593::/64 dev tun0 proto kernel metric 256 pref medium Using same network behind two interfaces won't work. You can't use same network for OpenVPN and Wireguard VPN, routing won't work. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/&

Re: [Shorewall-users] Re (n): (1)"shorewall status" and (2)$FW.

2020-11-30 Thread Tuomo Soini
ewall development is done. https://shorewall.org is generated from there. So https://shorewall.org is your primary documentation source still. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users ma

Re: [Shorewall-users] dhcrelay

2020-11-23 Thread Tuomo Soini
SW router. Am I right? That's not quite enough. When dhcp clients want to renew leases they need unicast dhcp access to your dns server. You can do that in rules with DHCPfwd macro. DHCPfwd(ACCEPT) lan1ibs:10.215.137.54 Macro will allow traffic to both directions. -- Tuomo Soini Foobar Linux

Re: [Shorewall-users] shorewall restart / compile.pl speed...

2020-11-20 Thread Tuomo Soini
a day. Remember to set shorewall-init or shorewall (but only one of these) to save ipsets. Or your shorewall will fail to start on boot. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shore

Re: [Shorewall-users] shorewall restart / compile.pl speed...

2020-11-18 Thread Tuomo Soini
On Wed, 18 Nov 2020 18:34:39 +0100 Marko Horn via Shorewall-users wrote: > do you know about a step by step guide for "ipset shorewall guide"? https://shorewall.org/blacklisting_support.htm#idm79 -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <h

Re: [Shorewall-users] shorewall restart / compile.pl speed...

2020-11-17 Thread Tuomo Soini
klisting. You don't even need to reload shorewall to update ipset blacklist. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.

Re: [Shorewall-users] mangle TPROXY

2020-10-05 Thread Tuomo Soini
On Mon, 5 Oct 2020 01:42:59 +0200 Vieri Di Paola wrote: > > I seriously doubt that the TLS handshake works when you try using > > HTTPS. The proxy is a 'man in the middle' in that case. You can't do transparent proxy for https. -- Tuomo Soini Foobar Linux services +358 40 52400

Re: [Shorewall-users] Keepalived ?

2020-09-18 Thread Tuomo Soini
be <http://www.aquabio.be/> > Oude Kaai 26 > 2300 Turnhout > Belgium > > Direct Line: +32 14 47 27 16 > Mobile: +32 495 50 38 95 > > Tel: +32 14 47 27 10 > Fax: +32 14 42 09 24 > > Please consider the environment before printing this e-mail > > > > Op

Re: [Shorewall-users] Keepalived ?

2020-09-17 Thread Tuomo Soini
al ip from firewall1 to firewall2 and network continues to work in some seconds. Nothing else changes but network flow moves from firewall to another. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shore

Re: [Shorewall-users] one rule for multiple source zones that match with a wildcard

2020-05-25 Thread Tuomo Soini
ore. This would work: DNS(ACCEPT) vpn1,vpn2,vpn3 $INT_DNS Or reverse idea, use all and exclude zones you don't want. DNS(ACCEPT) all!net $INT_DNS -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> pgpG9X6pmk41v.pgp Description: OpenPGP digital signa

Re: [Shorewall-users] Two separate providers for download and upload?

2020-02-01 Thread Tuomo Soini
hrough the 4G provider... > > Or, the opposite, create a sort of list of devices in my network (tv > box, tablet,..) and force them to be routed through the ADSL provider, > not wasting 4G traffic.. Exactly. -- Tuomo Soini Foobar Linux services +358 40 52

Re: [Shorewall-users] Shorewall6 documentation corrections

2019-12-23 Thread Tuomo Soini
rom 5.0+ documentation tree. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/shorewall-users

Re: [Shorewall-users] Shorewall6 documentation corrections

2019-12-20 Thread Tuomo Soini
ed. Reason: We must not document bugs. We need to fix them. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/shorewall-users

Re: [Shorewall-users] Shorewall6 documentation corrections

2019-12-20 Thread Tuomo Soini
-2001:470:a:227::10]:1000-1010 > Note: the internal ']-[' should be just a dash '-'. Ok. That is really a bug in shorewall ipv6 range parser. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___ Shorew

Re: [Shorewall-users] Weights on balance and fallback

2019-01-11 Thread Tuomo Soini
On Fri, 11 Jan 2019 16:20:53 +0100 Norman Henderson wrote: > Trouble is, it doesn't look like it works that way - but I need to > watch it for a while. Anyway I guess it isn't really Shorewall doing > this, rather iproute2. No. It's kernel which handles routing. -- Tuomo Soini Foo

Re: [Shorewall-users] Invalid Zone Name

2019-01-06 Thread Tuomo Soini
%s ". That will give you more characters to spend in zone names. For every two characters you strip out from LOGFORMAT you get one character more for zone names. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> ___

Re: [Shorewall-users] Making shorewall.net accessible with https

2019-01-04 Thread Tuomo Soini
On Fri, 4 Jan 2019 10:17:12 -0800 Tom Eastep wrote: > We have no plans to make the Shorewall web sites and mirrors > accessible via https. Finnish mirror is only accessible with https. Try https://shorewall.fi/. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy

Re: [Shorewall-users] ICMP6 RA replies not being sent out

2018-06-05 Thread Tuomo Soini
On Mon, 04 Jun 2018 21:12:54 -0400 "Brian J. Murrell" wrote: > On Mon, 2018-06-04 at 23:51 +0300, Tuomo Soini wrote: > > > > Update to centos 7 latest kernels (3.10.0-862.*.el7) will fix the > > issue. > > My Shorewall gateway is OpenWRT, so identif

Re: [Shorewall-users] ICMP6 RA replies not being sent out

2018-06-04 Thread Tuomo Soini
7) will fix the issue. Big ipv6 update was in kernel 3.10.0-862.el7. That eliminated ipv6 neighbour cache, just like ipv4 code already worked. -- Tuomo Soini Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> pgpyj3Cjgum2g.pgp D

Re: [Shorewall-users] Deprecated Actions in shorewall 5.1.12.1

2018-05-06 Thread Tuomo Soini
You are using the deprecated Drop default action. > Please see http://www.shorewall.net/Actions.html Please note: action.Reject is deprecated. Not REJECT. And same for action.Drop versus DROP. http://www.shorewall.net/Actions.html#Default And check for new shorewall.conf from 5.1.12.1 - you

Re: [Shorewall-users] ProxyNDP with radvd / DHCPv6 (i.e. not static configuration)

2018-01-09 Thread Tuomo Soini
complains about it not being a /64 but it works. /64 is absolute requirement for stateless autoconfiguration. It can not work properly on smaller network. -- Tuomo Soini <t...@foobar.fi> Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/> --

Re: [Shorewall-users] DNAT and UDP

2017-12-29 Thread Tuomo Soini
> Am I understanding correctly that Libreswan does -not- do NAT-T > properly? If so, is there some way to mitigate this? Libreswan does nat-t just fine. -- Tuomo Soini <t...@foobar.fi> Foobar Linux services +358 40 5240030 Foobar Oy <ht

Re: [Shorewall-users] DNAT and UDP

2017-12-28 Thread Tuomo Soini
ysconfig.txt for > IPSEC setup. As one of the Libreswan authors I'd note it's "Libreswan" - no capital letters in the middle of the name, please. When suggesting manual keying, please note it is horribly insecure and should not be used: https://tools.ietf.org/html/rfc8221#section-3 --

Re: [Shorewall-users] Tproxy + Squid + IPv6

2017-07-02 Thread Tuomo Soini
On Sun, 2 Jul 2017 12:14:14 +0100 Simon Hobson <li...@thehobsons.co.uk> wrote: > Tuomo Soini <t...@foobar.fi> wrote: > > > Reason for the issue is browser creates tcp connection with proxy, > > not with remote site so browser doesn't know tcp connection failed >

Re: [Shorewall-users] Tproxy + Squid + IPv6

2017-07-02 Thread Tuomo Soini
know tcp connection failed with destination site - so ipv6 to ipv4 fallback can't work. -- Tuomo Soini <t...@foobar.fi> Foobar Linux services +358 40 5240030 Foobar Oy <http://foobar.fi/> pgpG921nt5GOW.pgp Description: OpenPGP digit

Re: [Shorewall-users] Channel Bonding - All connection on Bonded interface blocked

2017-03-14 Thread Tuomo Soini
t; sets an IEEE > 802.3ad dynamic link aggregation policy which my router supports/is > configured. It's not about router - it's about switch your server is connected to. Switch must support 802.3ad for bonding to work. Only active-backup mode works with every switch without problems. -- Tu

Re: [Shorewall-users] Channel Bonding - All connection on Bonded interface blocked

2017-03-13 Thread Tuomo Soini
y one address is assigned. I am guessing that shorewall is > reading the ifcfg-enp4s0f* files directly rather that after the bond > is set up??? Shorewall only knows of what you have configured, shorewall doesn't read ifcfg files. If you configure bonding, leave slave interfaces out from shorewall

Re: [Shorewall-users] NPTv6

2016-12-26 Thread Tuomo Soini
On Mon, 26 Dec 2016 08:15:49 +0100 Luke Jordan <lujjor...@gmail.com> wrote: > Hi, > > it is possible to use NPTv6 for a multi-homing setup with shorewall6? What do you mean with NPTv6 ? -- Tuomo Soini <t...@foobar.fi> Foobar Linux services +358 40 5240030 Foobar

Re: [Shorewall-users] shorewall and Strongswan - possible incompatibility?

2016-12-03 Thread Tuomo Soini
sually tunnel type ipsecnat is what you want instead of tunnel type ipsec. -- Tuomo Soini <t...@foobar.fi> Foobar Linux services +358 40 5240030 Foobar Oy <http://foobar.fi/> -- Check out the vibrant tech commun

Re: [Shorewall-users] systemd shorewall[6].service file

2016-01-05 Thread Tuomo Soini
: > > [Unit] > > After=network-online.target > > > > Simply set LOCKFILE to the same value in both shorewall.conf and > shorewall6.conf. > > -Tom I did the ordering for services but that is wrong approach. Like using same LOCKFILE is. Correct thing is to dete

Re: [Shorewall-users] SW v5-specific "build50" script: OK for tarball build, fails @ rpm build ?

2015-11-09 Thread Tuomo Soini
get noarch-linux $@ >> $LOGFILE 2>&1 > > do_or_die do_rpmbuild "-ba $RPMDIR/SPECS/${2}.spec" > > teastep@gateway:~/shorewall/tools/build$ There is no taget called "noarch-linux" on any rpm based system I know of. It's "noarch". -- Tuo

Re: [Shorewall-users] Shorewall 5.0.0

2015-10-12 Thread Tuomo Soini
ers when I said 5.0.0 is out :-(. Another request by admins was this change to all config files: sed -i -e 's/Shorewall \ version\ 5/Shorewall/' Reason: shorewall version is not relevant on config files. Config file version is, but there is already ?VERSION for that. -- Tuomo Soini <t...

Re: [Shorewall-users] Shorewall 5.0.0

2015-10-11 Thread Tuomo Soini
ll software. Also there is a real problem in 5.0.0. Default value for LEGACY_RESTART=No - and old configs don't have this option! So this breaks all system with old configs now by causing traffic to stop during restart. -- Tuomo Soini <t...@foobar.fi> Foobar Linux services +358 40 524

Re: [Shorewall-users] Providers with same gateway different interface and IP

2015-01-06 Thread Tuomo Soini
try to modify/add config in providers file, then i get this error: Multi-isp is not correct way to configure multiple ip aliases. Check http://shorewall.net/Shorewall_and_Aliased_Interfaces.html to find out correct ways to handle multiple ip addresses. -- Tuomo Soini t...@foobar.fi Foobar

Re: [Shorewall-users] bad permission on /etc/shorewall/notrack

2014-02-14 Thread Tuomo Soini
. -- Tuomo Soini t...@foobar.fi Foobar Linux services +358 40 5240030 Foobar Oy http://foobar.fi/ signature.asc Description: PGP signature -- Android apps run on BlackBerry 10 Introducing the new BlackBerry 10.2.1 Runtime

Re: [Shorewall-users] lsm configuration issues...

2013-09-27 Thread Tuomo Soini
systems where you do something like this: Note, I only use lsm for ipv4 here. /etc/sysconfig/lsm: #!/bin/sh # # LSM to Shorewall Multi-ISP integration script # # Copyright © 2009-2013 Tuomo Soini t...@foobar.fi # DAEMON_COREFILE_LIMIT=unlimited VARDIR=$(/sbin/shorewall show vardir) if [ $1

Re: [Shorewall-users] Shorewall 4.5.2

2012-04-12 Thread Tuomo Soini
On Wed, 11 Apr 2012 15:42:58 -0600 Orion Poplawski or...@cora.nwra.com wrote: +PERLLIBDIR=${PREFIX}/share/perl5 I think this should be ${PREFIX}/share/perl5/vendor_perl accodring fedora perl packaging guidelines. Only system perl installs to /usr/share/perl5. -- Tuomo Soini t...@foobar.fi

Re: [Shorewall-users] new macros I use

2012-03-17 Thread Tuomo Soini
names generally are for protocols or software. macro.Prelude works for Prelude IDS This makes more sense in naming point. -- Tuomo Soini t...@foobar.fi Foobar Linux services +358 40 5240030 Foobar Oy http://foobar.fi

Re: [Shorewall-users] CentOS6/RHEL6 - net.nf_conntrack_max not applied

2012-03-13 Thread Tuomo Soini
. -- Tuomo Soini t...@foobar.fi Foobar Linux services +358 40 5240030 Foobar Oy http://foobar.fi/ -- Keep Your Developer Skills Current with LearnDevNow! The most comprehensive online learning library for Microsoft developers

Re: [Shorewall-users] CentOS6/RHEL6 - net.nf_conntrack_max not applied

2012-03-13 Thread Tuomo Soini
change things. -- Tuomo Soini t...@foobar.fi Foobar Linux services +358 40 5240030 Foobar Oy http://foobar.fi/ signature.asc Description: PGP signature -- Keep Your Developer Skills Current with LearnDevNow! The most

Re: [Shorewall-users] CentOS6/RHEL6 - net.nf_conntrack_max not applied

2012-03-13 Thread Tuomo Soini
was not updated. So just like I suspected: running shorewall-init causes conntrack to load early enough for sysctl. -- Tuomo Soini t...@foobar.fi Foobar Linux services +358 40 5240030 Foobar Oy http://foobar.fi/ signature.asc Description: PGP signature

Re: [Shorewall-users] TC issues after updating from RHEL4 to RHEL6

2011-10-12 Thread Tuomo Soini
*full/10 2 default eth2 3 2*full/10 8*full/10 2 -- Tuomo Soini t...@foobar.fi Foobar Linux services +358 40 5240030 Foobar Oy http://foobar.fi/ -- All the data continuously generated in your IT infrastructure contains

Re: [Shorewall-users] rackspace cloud shorewall routing problem

2010-05-05 Thread Tuomo Soini
. I guess it's unpatched centos - there was that kind of bug in rhel-5 iptables which was fixed by iptables update. -- Tuomo Soini t...@foobar.fi Foobar Linux services +358 40 5240030 Foobar Oy http://foobar.fi

Re: [Shorewall-users] Kernel Panic on Masq Enable with Shorewall 4.4.8 2.6.27.45-0.1-default #1 SMP

2010-05-02 Thread Tuomo Soini
bug in kernel so this is SuSE issue. Btw. 4.4.8 is not latest shorewall. 4.4.8.4 is. -- Tuomo Soini t...@foobar.fi Foobar Linux services +358 40 5240030 Foobar Oy http://foobar.fi

Re: [Shorewall-users] isusable/swping script

2010-02-17 Thread Tuomo Soini
Shorewall warn me : ERROR: Interface eth2.303 is not usable -- Provider freenew (1024) Cannot be Added Terminated I guess you don't have interface option optional for eth2.303. You must have interface option optional for every interface swping might return failed. -- Tuomo Soini t

Re: [Shorewall-users] shorewall6-lite's shorecap sourcing /usr/share/shorewall-lite/lib.base?

2009-12-07 Thread Tuomo Soini
Simon Matter wrote: Somehow the 4.4.4.2 patches are not the way they should be. You may want to check your build scripts I think. patch-6-4.4.4.2 and patch-6-lite-4.4.4.2 seem to be wrong. That's propably because 4.4.4.1 was skipped so there was no 4.4.4.1 to compare against. -- Tuomo Soini

Re: [Shorewall-users] Shorewall (Openswan) IPSEC VPN MASQ Problem

2009-08-13 Thread Tuomo Soini
recognizes NETKEY and will never create ipsec0 interface like openswan + klips. -- Tuomo Soini t...@foobar.fi Foobar Linux services +358 40 5240030 Foobar Oy http://foobar.fi/ -- Let Crystal Reports handle the reporting - Free

Re: [Shorewall-users] Shorewall and NIC bonding

2009-07-10 Thread Tuomo Soini
and it will work. -- Tuomo Soini t...@foobar.fi Foobar Linux services +358 40 5240030 Foobar Oy http://foobar.fi/ -- Enter the BlackBerry Developer Challenge This is your chance to win up to $100,000 in prizes

Re: [Shorewall-users] why ACCEPT for intra-zone traffic?

2008-05-19 Thread Tuomo Soini
this hard coded policy? Right now I've had to add dmz dmz REJECT to my file in order to get the behaviour I want. Try dmz dmz REJECT info instead. If you want to prevent that traffic, you propably want to log it too. You have special setup if you want to protect against zone2zone traffic. - -- Tuomo

Re: [Shorewall-users] Bug in Multi-ISP support

2007-08-23 Thread Tuomo Soini
3.4 versions questionable because only real changes to shorewall-shell-4 and shorewall-common-4 are packaging related. - -- Tuomo Soini [EMAIL PROTECTED] Linux and network services +358 40 5240030 Foobar Oy http://foobar.fi/ -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.6 (GNU/Linux

Re: [Shorewall-users] No Startup at Boot

2007-07-16 Thread Tuomo Soini
which is vital part of shorewall version to version update requirements. - -- Tuomo Soini [EMAIL PROTECTED] Linux and network services +358 40 5240030 Foobar Oy http://foobar.fi/ -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.6 (GNU/Linux