Re: [Shorewall-users] Can I ignore failing rules?

2024-02-28 Thread Peter Thurner | Blunix GmbH via Shorewall-users
, Feb 28, 2024 at 09:31:16PM +0200, Tuomo Soini wrote: > On Wed, 28 Feb 2024 19:45:55 +0100 > Peter Thurner | Blunix GmbH via Shorewall-users > wrote: > > > I am aware of that, however sometimes there isn't really a much > > better way than using dns names. that doesn

Re: [Shorewall-users] Can I ignore failing rules?

2024-02-28 Thread Peter Thurner | Blunix GmbH via Shorewall-users
well thats nice. didnt know that! my case is a bit different but still VERY interesting post! On Wed, Feb 28, 2024 at 07:36:16PM +0100, Benny Pedersen wrote: > Peter Thurner | Blunix GmbH via Shorewall-users skrev den 2024-02-28 17:49: > > Hello shorewall users, > > > > is

Re: [Shorewall-users] Can I ignore failing rules?

2024-02-28 Thread Peter Thurner | Blunix GmbH via Shorewall-users
Wed, 28 Feb 2024 17:49:37 +0100 > Peter Thurner | Blunix GmbH via Shorewall-users > wrote: > > > Hello shorewall users, > > > > is there a way to ignore failing rules in shorewall, specifically if > > /etc/shorewall/rules contains something like > > > &g

[Shorewall-users] Can I ignore failing rules?

2024-02-28 Thread Peter Thurner | Blunix GmbH via Shorewall-users
Hello shorewall users, is there a way to ignore failing rules in shorewall, specifically if /etc/shorewall/rules contains something like ACCEPT local pub:this.domain.doesnt.exist.com tcp 443 ? with kind regards, Peter Thurner CEO Blunix GmbH -- Blunix GmbH Glogauer Straße 21 10999 Berlin

Re: [Shorewall-users] Filtering on Ether type, not port

2022-03-02 Thread Peter Humphrey
about opening port 80 to the FB? Won't that just allow packets in from the Internet? -- Regards, Peter. ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/shorewall-users

[Shorewall-users] Filtering on Ether type, not port

2022-03-02 Thread Peter Humphrey
have a way to filter on the Ether type? -- Regards, Peter. ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/shorewall-users

[Shorewall-users] Re (n): (1)"shorewall status" and (2)$FW.

2020-11-30 Thread peter
is true but incomplete. Use of the "physical=" option is not only relevant to multiple bridges. There is no bridge here but "physical=wlxa0f3c10a28f7" can be used. Regards,... Peter E. -- Tel: +1 604 670 0140Bcc:

[Shorewall-users] Re (2): Re (1)"shorewall status" and (2)$FW.

2020-11-30 Thread peter
ng. ;-) Thanks. The pages at shorewall.org suffice, more or less. I tripped on the intended use of the params file, NET_IF and the "physical=" option. The replies from Justin and Matt helped to clear the fog. Regards, ... P. -- Tel: +1 604 670 0140

[Shorewall-users] Re (1)"shorewall status" and (2)$FW.

2020-11-29 Thread peter
n /etc/shorewall/params. I remain puzzled that shorewall worked here for years without NET_IF in params. The default route is available without /etc/shorewall/params. In any case, progress here. Thanks for the help, ... P. -- Tel: +1 604 670

[Shorewall-users] Re (2): (1)"shorewall status" and (2)$FW.

2020-11-29 Thread peter
T_IF = $IFACE pre-down NET_IF = '' Advice from someone familiar with the intended operation of a WiFi 'net connection would really help. Thanks, ... P. -- Tel: +1 604 670 0140 Bcc: peter at easthope. ca

[Shorewall-users] (1)"shorewall status" and (2)$FW.

2020-11-29 Thread peter
From: Justin Pryzby > I guess it should be while shorewall is running. Sorry. Try now. http://easthope.ca/shorewall.dump.txt ... P. -- Tel: +1 604 670 0140Bcc: peter at easthope. ca ___ Shorewall-us

[Shorewall-users] Re (2): (1)"shorewall status" and (2)$FW.

2020-11-29 Thread peter
,... P. -- Tel: +1 604 670 0140Bcc: peter at easthope. ca ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/shorewall-users

Re: [Shorewall-users] (1)"shorewall status" and (2)$FW.

2020-11-29 Thread peter
config or preferably a shorweall dump ? Click here . http://easthope.ca/shorewall.dump.txt Regards, ... P. -- Tel: +1 604 670 0140 Bcc: peter at easthope. ca ___ Shorewall-users mailing list Shorewall

[Shorewall-users] (1)"shorewall status" and (2)$FW.

2020-11-29 Thread peter
a ... Non-authoritative answer: Name: google.ca Address: 172.217.3.195 Name: google.ca Address: 2607:f8b0:400a:809::2003 Any suggestion about the failure of name resolution? Thanks, ... Peter E. -- Tel: +1 604 670 0140Bcc: peter at easthope. ca __

[Shorewall-users] Re (2): Link in the Wikipedia.

2020-11-19 Thread peter
rticle needs inline citations. Can someone familiar with IT publications help? Unfortunately I don't know the subject well enough. TTFN, ... P. -- Tel: +1 604 670 0140 Bcc: peter at eastho

[Shorewall-users] Link in the Wikipedia.

2020-11-19 Thread peter
rewall.org. Is the inconsistency desirable? Any objection to a revision? Thanks,... P. -- Tel: +1 604 670 0140 Bcc: peter at easthope. ca ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge

[Shorewall-users] Link in the Wikipedia.

2020-11-19 Thread peter
rewall.org. Is the inconsistency desirable? Any objection to a revision? Thanks,... P. -- Tel: +1 604 670 0140 Bcc: peter at easthope. ca ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge

Re: [Shorewall-users] IPv4 or IPv6

2020-10-31 Thread peter
Thanks so much for answering! seems like I have to makee another installation! Youre the best! /peter October 31, 2020 9:25 PM, "Roberto C. Sánchez" wrote: > On Sat, Oct 31, 2020 at 07:56:27PM +, pe...@kahn.nu wrote: > >> I have noticed that there are 4 and i6 releas

[Shorewall-users] IPv4 or IPv6

2020-10-31 Thread peter
I have noticed that there are 4 and i6 releases of the firewall. So... Do i have to install both? Will shorewall protect against ipv4 attacks if I I have only installed shorewall 6 protection. Or what? Sorry for the stupid question. I could'nt easily find the answer from your website. /Peter

Re: [Shorewall-users] Strongswan Route-based IPSec - FORWARD REJECT

2020-10-29 Thread Peter Hurtenbach via Shorewall-users
out --pol none" added. I have now removed this zone, the mentioned iptables options will not be added and the traffic flows. Does anyone understand this behavior? Is this a unsupported combination? Thanks, Peter On 10/28/20 5:54 PM, Peter Hurtenbach via Shorewall-users wrote: Strongsw

[Shorewall-users] Strongswan Route-based IPSec - FORWARD REJECT

2020-10-28 Thread Peter Hurtenbach via Shorewall-users
:b4:f6:08:00 SRC=10.0.5.8 DST=10.17.14.6 LEN=60 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=22 DPT=39234 WINDOW=65160 RES=0x00 ACK SYN URGP=0 I also have tried the option routeback on the interface. Can anyone help me with this behavior? Thanks

[Shorewall-users] Problem routing traffic from my lan to a machine behind ipsec.

2020-10-10 Thread Peter Nunn
complete or not. Thanks so much in advance. A linux bloke with enough networking to be dangerous. Peter. shorewall_dump.txt.gz Description: application/gzip ___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https

[Shorewall-users] Sequencing interface configuration and shorewall under systemd.

2020-01-20 Thread Peter Easthope
/shorewall/wait4ifup exists here. Is it still necessary? Can anyone have a clever way of sequencing with systemd configurations? Thanks, ... Peter E. -- Tel.: +1 604 670 0140 Bcc: peter at easthope. ca ___ Shorewall-users mailing list

Re: [Shorewall-users] Can't access the internet from behind the firewall

2018-05-10 Thread Peter Hurtenbach
Hi, you have to set up source nat (masquerading) for the interface associated with your net zone, otherwise the traffic will go out with the clients ip to the gateway. You can simply validate that with an tcpdump on your net interface. > Am 10.05.2018 um 22:07 schrieb David Ventura

[Shorewall-users] Re (2): Masquerading a port?

2018-01-18 Thread peter
simplify. Analogous to vector notation avoiding individual elements. Thanks again, ... Peter E. -- 123456789 123456789 123456789 123456789 123456789 123456789 123456789 Tel: +1 360 639 0202 Pender Is.: +1 250 629 3757 http://easthope.ca/Peter.html B

[Shorewall-users] Re (2): Shorewall 5.1.11

2018-01-18 Thread peter
l study further. Certainly tips are welcome. Regards, ... Peter E. -- 123456789 123456789 123456789 123456789 123456789 123456789 123456789 Tel: +1 360 639 0202 Pender Is.: +1 250 629 3757 http://easthope.ca/Peter.html Bcc: peter

[Shorewall-users] Masquerading a port?

2018-01-18 Thread peter
P.s. The question in 5 words: how is a port masqueraded? Thanks, ... Peter E. -- 123456789 123456789 123456789 123456789 123456789 123456789 123456789 Tel: +1 360 639 0202 Pender Is.: +1 250 629 3757 http://easthope.ca/Peter.html

Re: [Shorewall-users] Correction: Configuration for a HTTP to HTTPS tunnel.

2018-01-18 Thread peter
Shorewall wrote, ERROR: Unknown Interface (954) /etc/shorewall/rules (line 9) OK, yes, 954 is port. The idea is to take any ORIGDEST with port 954. Conceptually, 0.0.0.0-255.255.255.255:954 or 0.0.0.0:954-255.255.255.255:954. Possible? Ideas? Thanks, ... Peter E

Re: [Shorewall-users] Configuration for a HTTP to HTTPS tunnel.

2018-01-15 Thread peter
ct from the alias port 954 to the HTTPS port 443. I haven't found an acceptable notation for the interface, indicated by *. Is this possible? Thanks,... Peter E. -- 123456789 123456789 123456789 123456789 123456789 123456789 123456789 Tel: +1 360 639 0202 Pende

[Shorewall-users] Configuration for a HTTP to HTTPS tunnel.

2018-01-14 Thread peter
, ... Peter E. -- 123456789 123456789 123456789 123456789 123456789 123456789 123456789 Tel: +1 360 639 0202 Pender Is.: +1 250 629 3757 http://easthope.ca/Peter.html Bcc: peter at easthope. ca

[Shorewall-users] Please take this as feature requests

2014-03-05 Thread Peter Littmann
the file command to detect that this file is ASCII text. No, it will consult mc.ext where it takes the information that this file should be viewed with odt2txt. This will not work. So a user might become a problem or at least gets a false idea about the format of this file.   Peter

[Shorewall-users] [shorewall-users] params file in /etc/shorewall/puppet not read

2011-12-02 Thread Peter Mumenthaler
VARDIR is /var/lib/shorewall LIBEXEC is /usr/libexec Attached you find the output of: /sbin/shorewall trace start 2 /tmp/trace Thanks for any help in advance. cheers peter -- Peter Mumenthaler Linux System-Ingenieur Puzzle ITC GmbH www.puzzle.ch Telefon +41 31 370 22 00 Direkt +41 31 370 22 34

[Shorewall-users] Route filtering, martian logging network connectivity.

2011-09-27 Thread PETER EASTHOPE
/peter# shorewall start   ... Starting Shorewall Initializing... Setting up Route Filtering...    WARNING: Cannot set route filtering on MainBoard Setting up Martian Logging...    WARNING: Cannot set Martian logging on MainBoard Setting up Traffic Control... Preparing iptables-restore input

[Shorewall-users] VPN routing on a 1 NIC router

2011-08-25 Thread Peter Lindeman
is not being sended to the machine on the local lan. Anybody has an idea where to look or what ever other information do I need to post to make more clear what is going wrong? Thanks! Peter -- EMC VNX: the world's simplest storage

Re: [Shorewall-users] iptables defunct

2011-06-19 Thread peter mcgregor
On 17/06/11 10:56 PM, David Watkins wrote: Are my shorewall restarts causing the problem? I wanted a static ip address but I wasn't able to get one for this user. Can you use their MAC address? It is a good suggestion but I thought about this for a while, did some investigation and realised

Re: [Shorewall-users] iptables defunct

2011-06-19 Thread peter mcgregor
On 17/06/11 10:56 PM, David Watkins wrote: Are my shorewall restarts causing the problem? I wanted a static ip address but I wasn't able to get one for this user. Can you use their MAC address? It is a good suggestion but I thought about this for a while, did some investigation and

Re: [Shorewall-users] iptables defunct

2011-06-19 Thread peter mcgregor
server assign a static ip address to their particular MAC address. Ian. Its not my server and for some reason their ISP does not want to give out a static ip address. I've been told that it may be because the country is very controlled. eg they are not allowed to use skype. Peter

Re: [Shorewall-users] iptables defunct

2011-06-19 Thread peter mcgregor
of this.) In 6 months time I may have to come up with another solution. cheers peter -- EditLive Enterprise is the world's most technically advanced content authoring tool. Experience the power of Track Changes, Inline

[Shorewall-users] howto go against an ddos attack

2011-03-01 Thread Jensen, Peter
Hello list, Recently i have had one of my boxes attacked with a ddos attack. It was all coming from 1 ip address so I made the rule : DROPnet:ip $FW ANY This however did not help much for the load coming onto the box, asif it wasn't working properly. When

[Shorewall-users] params file not being parsed correctly

2009-12-14 Thread Peter Wrangell
would be causing this? Also, the compiler is set to shell, and the params file is exported in shorewall.conf. Kind Regards, Peter Wrangell -- Return on Information: Google Enterprise Search pays you back Get the facts

Re: [Shorewall-users] params file not being parsed correctly

2009-12-14 Thread Peter Wrangell
. As they say, if everything else fails, take a look at the source. Kind Regards, Peter -Original Message- From: Tom Eastep [mailto:teas...@shorewall.net] Sent: Mon 12/14/2009 5:48 PM To: Shorewall Users Subject: Re: [Shorewall-users] params file not being parsed correctly Peter

[Shorewall-users] masqing a zone connected _via_ a tun.

2009-03-17 Thread PETER EASTHOPE
As I understand, the routes specified in /etc/openvpn/myvpn do not exist when shorewall starts. What is the conventional solution? Thanks,... Peter E. -- http://members.shaw.ca/peasthope/ http://carnot.yi.org/ = http://carnot.pathology.ubc.ca

[Shorewall-users] Improvements in shorewall-interfaces.man etc.

2008-10-31 Thread PETER EASTHOPE
clients. 2. Can the effect of the dhcp option be described briefly in one or two sentences? Eg. This option specifies that DHCP datagrams be allowed to traverse the interface. Regards, ... Peter E. -- http://members.shaw.ca/peasthope/ http://carnot.yi.org/ = http

[Shorewall-users] FTP and etc.

2008-08-25 Thread PETER EASTHOPE
. Any insights, hints or tips will be appreciated, Thanks, ... Peter E. -- http://members.shaw.ca/peasthope/ http://carnot.yi.org/ = http://carnot.pathology.ubc.ca/ - This SF.Net email is sponsored by the Moblin Your

[Shorewall-users] Re (2): FTP and etc.

2008-08-25 Thread PETER EASTHOPE
at UBC is similar but has no such problems. Regards, ... Peter E. - This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based applications with Moblin SDK win great

Re: [Shorewall-users] Port Forwarding .... (getting the right settings)

2008-08-07 Thread peter
? Peter Tom Eastep wrote: peter wrote: Hello Tom, thank you for your response and your patience :) I have appended the output of the Shorewall dump. I had to cut a chunk out of the middle of this file (most of the conntrack table) since it was originally 13.5MB Deluge is running on a client

Re: [Shorewall-users] Port Forwarding .... (getting the right settings)

2008-08-07 Thread peter
no performance but that is no doubt another issue. Why this did not work the first time round is not something I will pretend to understand . Many thanks for your help :) Peter Tom Eastep wrote: peter wrote: Thanks for the comments Tom. I have changed the settings and I think

[Shorewall-users] Port Forwarding .... (getting the right settings)

2008-08-06 Thread peter
Ubuntu 7.10 server, 8.04 client. I seem to have a problem opening ports. I know this since when I test the opened ports with Deluge it tells me that the ports are closed. The router is a Linksys AG241 v2 with firmware 2.01.03. This has an IP of 192.168.1.1 and is connected to the server on

[Shorewall-users] Re (2): :P notation in http://www.shorewall.net/VPNBasics.html

2008-07-18 Thread PETER EASTHOPE
ZONE openvpn:P Z11.2.3.4 ? By the way, Shorewall is certainly among best documented of open source softwares. Thanks,... Peter E. -- http://members.shaw.ca/peasthope/ http://carnot.yi.org/ = http://carnot.pathology.ubc.ca

[Shorewall-users] Routing through an openvpn tunnel.

2008-07-18 Thread PETER EASTHOPE
the routing? Is routing a separate matter? Thanks, ... Peter E. -- http://members.shaw.ca/peasthope/ http://carnot.yi.org/ = http://carnot.pathology.ubc.ca/ - This SF.Net email is sponsored by the Moblin Your

[Shorewall-users] :P notation in http://www.shorewall.net/VPNBasics.html

2008-07-17 Thread PETER EASTHOPE
with a meaning that eludes me? Thanks, ... Peter E. -- http://members.shaw.ca/peasthope/ http://carnot.yi.org/ = http://carnot.pathology.ubc.ca/ - This SF.Net email is sponsored by the Moblin Your Move Developer's

[Shorewall-users] SOURCE = DEST in a policy or rule

2008-07-10 Thread PETER EASTHOPE
loc I've made a small effort to find the answer in the documentation and failed of course. Thanks, ... Peter E. -- http://members.shaw.ca/peasthope/ http://carnot.yi.org/ = http://carnot.pathology.ubc.ca

Re: [Shorewall-users] IPSec Passthrough fails when using CiscoVPNclient

2007-04-17 Thread Peter Wilson
using CiscoVPNclient Peter: We had to deal with this some weeks ago. I think the only part you have missed is the NAT. Cisco VPN requires the desktop has a valid IP. So just create a NAT, and you'll be OK. If you still has problems, don't hesitate to contact me and we can do some test together

[Shorewall-users] IPSec Passthrough fails when using Cisco VPN client

2007-04-16 Thread Peter Wilson
192.168.118.118 and 203.110.142.69. If I have missed anything or you need further information please let me know. Thankyou in advance, Peter status.txt.gz Description: status.txt.gz - This SF.net email is sponsored by DB2 Express

Re: [Shorewall-users] IPSec Passthrough fails when using Cisco VPN client

2007-04-16 Thread Peter Wilson
fails when using Cisco VPN client Peter Wilson wrote: I have Shorewall running as an office gateway performing NAT for local clients to access Internet. There is a policy allowing full access from loc - net. Problem arrises when trying to connect a Cisco VPN client to a VPN server

Re: [Shorewall-users] Adoption rate (Was: IPSEC NAT-T IKE failswhen policy is $FW2net REJECT.)

2007-03-23 Thread Peter Wagner
Hi, Thank you shorewall developers your scripts are runable in embedded linx devices saves me a lot of config time . Realy nice . Have a nice day greets - Take Surveys. Earn Cash. Influence the Future

Re: [Shorewall-users] Shorewall-users Digest, Vol 6, Issue 4

2006-11-03 Thread Peter Haijen
Thanks, the ethtool trick solved my problem.I did read about it on your web page, but somehow I was under the impression that this fix would only fix some UDP checksum problem, and did not bother to try it because I was able to ping, but not able to ssh/www. Sorry. Regards,Peter

[Shorewall-users] Problem configuring shorewall

2006-11-02 Thread Peter Haijen
. (www,ssh towards other hosts from 10.0.0.3 does not work either, gw is 10.0.0.1)Very puzzled as to what is wrong here thx for any help you may offer!Peter status.txt.gz Description: GNU Zip compressed data trace.cap Description: Binary data