[Shorewall-users] DNAT from localhost to other host

2021-12-02 Thread shacky
Hi, I'm trying to setup a DNAT which forwards requests originally directed to 127.0.0.1:8404 to 10.1.3.253:8404. /etc/shorewall/zones: #ZONE TYPEOPTIONS IN OUT # OPTIONS OPTIONS fw firewall lan

[Shorewall-users] IP address routing

2012-06-21 Thread shacky
Hi. I have one server with Hetzner (www.hetzner.de), I installed a Proxmox VE and I activated one additional IP address and one failover IP address, so I have 3 IP addresses: - the main IP address (Proxmox) - one additional IP address (Virtual Machine) - one failover IP address that needs to be r

[Shorewall-users] Gateway in the LAN

2010-03-26 Thread shacky
Hi. I have some clients that uses a Shorewall system as default gateway on the LAN network 192.168.1.0/24. The Shorewall system has a static route that redirect requests to 192.168.10.0/24 to the gateway 192.168.1.253, and it works of course. How I can let all clients on 192.168.1.0/24 go to 192.1

[Shorewall-users] REDIRECT rule for localhost addresses

2009-05-14 Thread shacky
Hi. I'm using the following REDIRECT rule to redirect to port 125 all traffic directed to port 25: REDIRECTnet 125 tcp 25 Now I want a similar rule for localhost traffic too, making this scenario: If I ask for 127.0.0.1:25 I have to get 127.0.0.1:125,

[Shorewall-users] Shorewall with VMWare and bridged interfaces

2008-04-02 Thread shacky
I'm configuring Shorewall on a server running VMWare which is using bridged interfaces to the virtual machines. How I have to setup the rules for the virtual, which have an own IP address on the bridged interface of VMWare? Thank you very much for your help! Bye. -

[Shorewall-users] Shorewall and DNS

2008-01-17 Thread shacky
Hi. I have to configure a DNAT rule in Shorewall with a DNS hostname as destination of the DNAT, because the destination host could be changed sometimes, but the port needs to be the same. If I configure a DNAT rule using a DNS hostname (for example "myhost.mylan.local:12345", Shorewall query the

Re: [Shorewall-users] L7-Filter

2007-11-27 Thread shacky
> However, if you want to use L7-filter, just use the NFQUEUE target in > Shorewall-perl 4.0.6 to send the traffic you want to be filtered by > L7-flter to NFQUEUE. So are you advising me to use ipp2p? Some people told me that L7-Filter is better than ipp2p, and I like it because it can recognise

Re: [Shorewall-users] How to block p2p

2007-11-26 Thread shacky
> It is possible, somewhat unpolished, slower than it ought to be, and > less than perfectly reliable. All that for quite a significant amount > of work in setting it up. Couldn't I test it? How I can use L7-Filter with Shorewall? Or you advise me to use a proxy instead of L7-Filter?

[Shorewall-users] L7-Filter

2007-11-26 Thread shacky
Hi! How I can use L7-Filter (http://l7-filter.sourceforge.net/) with Shorewall? Thank you very much! Bye. - This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.co

Re: [Shorewall-users] How to block p2p

2007-11-26 Thread shacky
What about using the Application Layer Packet Classifier for Linux (http://l7-filter.sourceforge.net/) to block p2p programs? A friend of mine told me that in his college he can't use Emule for all, and HTTPS connections are not disabled. The network of the college allows the connections to the 22,

Re: [Shorewall-users] How to block p2p

2007-11-26 Thread shacky
> Short answer - you can't ! So the only way is to remove the masquerading and to use a Squid and allow only the port 80 (not the 443) and disable the connect method on the port 80? - This SF.net email is sponsored by: Micros

[Shorewall-users] How to block p2p

2007-11-26 Thread shacky
Hi. How I can block all connections from the p2p programs (Emule, Bittorrent, etc.) with Shorewall? Thank you very much. Bye. - This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 200

[Shorewall-users] Traffic shaping

2007-11-26 Thread shacky
Hi. I have a firewall configured with Shorewall with 2 zones: loc and net. The firewall does the masquerading from the loc to the net zones. I want to make a traffic shaping to let me to have a certain piece of bandwith when I connect to the firewall from my fixed IP address, independently from th

[Shorewall-users] Martian source

2007-11-22 Thread shacky
Hi. I'm getting a lot of messages in my /var/log/syslog about martian source from a lot of clients of my LAN network: kernel: martian source 255.255.255.255 from 192.168.8.191, on dev eth0 kernel: martian source 192.168.8.2 from 192.168.8.103, on dev eth0 What's the problem? Thank you very much

Re: [Shorewall-users] ip6tables can't initialize ip6tables table filter

2007-11-15 Thread shacky
> Also, 'Invalid argument' iptables errors often indicate that your iptables > is incompatible with your kernel. Did you build the iptables in the domU > against the domU kernel source tree? I don't know, as I am not the administrator of the dom0 and I have not compiled the domU kernel... ---

Re: [Shorewall-users] pptpd vpn and Shorewall

2007-11-15 Thread shacky
I solved it, I didn't allowed the VPN to access the loc zone and viceversa... I was stupid! :-) Thank you very much! Bye!! - This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. h

[Shorewall-users] ip6tables can't initialize ip6tables table filter

2007-11-15 Thread shacky
Hi list! I am configuring Shorewall on a Xen domU virtual machine. I configured only the zones, interfaces, rules, policy and shorewall.conf files. When I run "shorewall check" there aren't no problems, but when I try to start shorewall I get this error a lot of time: iptables: Invalid argument i

[Shorewall-users] pptpd vpn and Shorewall

2007-11-15 Thread shacky
Hi. I configured a pptpd server and my /etc/shorewall/tunnels file is the following: #TYPE ZONEGATEWAY GATEWAY # ZONE pptpserver net 0.0.0.0/0 - I can connect to the VPN server, but I can't reach the machines in my LAN (th

Re: [Shorewall-users] ERROR: Unknown Host (-) /etc/shorewall/tunnels

2007-11-01 Thread shacky
> You need 0.0.0.0/0 in the GATEWAY column. Thank you very much! Now it works! But this is not documented... Bye! - This SF.net email is sponsored by: Splunk Inc. Still grepping through log files to find problems? Stop. Now

[Shorewall-users] ERROR: Unknown Host (-) /etc/shorewall/tunnels

2007-11-01 Thread shacky
Hi. I have a pptpd server on the wan interface (net), so I configured the /etc/shorewall/tunnels file as follow: #TYPE ZONEGATEWAY GATEWAY # ZONE pptpserver net When I check the shorewall configuration I get this error: ERROR: Unkn

[Shorewall-users] LOC to DMZ

2007-10-30 Thread shacky
Hi. I'm configuring a Shorewall system with 3 zones (net, loc, dmz). To access to the dmz from the net I configured some DNAT rules like this: DNAT net dmz:192.168.2.1 tcp 22 With this rules I opened only some ports. Now I'm thinking about the connection from loc to dmz. I want

Re: [Shorewall-users] Web log viewer

2007-10-12 Thread shacky
Ok, I decided to start to write my own Ulogd-php version... :-) - This SF.net email is sponsored by: Splunk Inc. Still grepping through log files to find problems? Stop. Now Search log events and configuration files using AJA

[Shorewall-users] Web log viewer

2007-10-11 Thread shacky
Hi. What system or software are you using to show the iptables log files (for example the dropped packages tagged as LOG in the Shorewall rules)? Thank you very much! Bye. - This SF.net email is sponsored by: Splunk Inc. Stil