[Shorewall-users] DNAT issue

2012-09-05 Thread Gábor Majoros
Hi, Sorry, not an experienced shorewall user, this is my first basic setup. This starts to drive me crazy. I wanted to use DNAT to forward port 33890 to an internal machine (windows) port 3389. To reach my workstation when I'm not home. In my rules : DNAT:debug net loc:192.168.0.11:3389

Re: [Shorewall-users] DNAT issue

2012-09-05 Thread Tom Eastep
Gábor Majoros wrote: Hi, Sorry, not an experienced shorewall user, this is my first basic setup. This starts to drive me crazy. I wanted to use DNAT to forward port 33890 to an internal machine (windows) port 3389. To reach my workstation when I'm not home. In my rules : DNAT:debug

Re: [Shorewall-users] DNAT issue

2012-09-05 Thread Gábor Majoros
Hi Tom, Apologies for bothering... Previously a very few FAQ was working for me (no offense for anyone) thus tried the list. Your FAQ is excelent. This case masq did the trick as the SW box is not my dgw. Have a pleasant day. Regards, On 5 September 2012 17:58, Tom Eastep

Re: [Shorewall-users] DNAT Issue

2008-11-16 Thread Robert K Coffman Jr. -Info From Data Corp.
I've looked through the FAQ and Troubleshooting guides but I'm still having problems getting a dnat rule to work Is it possible your ISP blocks connections to high ports? - This SF.Net email is sponsored by the Moblin Your

Re: [Shorewall-users] DNAT Issue

2008-11-16 Thread Shorewall Geek
Ben Solwitz wrote: I've looked through the FAQ and Troubleshooting guides but I'm still having problems getting a dnat rule to work. I am trying to forward connections on port 23389 from my public ip 76.190.252.72 http://76.190.252.72 to a computer on my network at 192.168.0.12

Re: [Shorewall-users] DNAT Issue

2008-11-16 Thread Shorewall Geek
Shorewall Geek wrote: Ben Solwitz wrote: I've looked through the FAQ and Troubleshooting guides but I'm still having problems getting a dnat rule to work. I am trying to forward connections on port 23389 from my public ip 76.190.252.72 http://76.190.252.72 to a computer on my network at

Re: [Shorewall-users] DNAT Issue

2008-11-16 Thread Shorewall Geek
Shorewall Geek wrote: Shorewall Geek wrote: Ben Solwitz wrote: I've looked through the FAQ and Troubleshooting guides but I'm still having problems getting a dnat rule to work. I am trying to forward connections on port 23389 from my public ip 76.190.252.72 http://76.190.252.72 to a computer

Re: [Shorewall-users] DNAT Issue

2008-11-16 Thread Ben Solwitz
Looks like that was the problem, thanks for the help, and sorry for asking a dumb question. Ben On Sun, Nov 16, 2008 at 1:30 PM, Shorewall Geek [EMAIL PROTECTED]wrote: Shorewall Geek wrote: Shorewall Geek wrote: Ben Solwitz wrote: I've looked through the FAQ and Troubleshooting guides

[Shorewall-users] DNAT Issue

2008-10-01 Thread Rob Hicks
Hi. Im setting up a web farm test lab. I have a number of machines in the test last on a dmz zone on network 10.20.30.0. The test lab firewall has two NICS. One (eth0) has two ip addresses, eth0 10.161.101.40 and eth0:0 10.161.10.49. The other one, eth1 is on a private network, 10.20.30.0.

Re: [Shorewall-users] DNAT Issue

2008-10-01 Thread Martin Leben
Rob Hicks wrote: Hi. Hi, The test lab firewall has two NICS. One (eth0) has two ip addresses, eth0 10.161.101.40 and eth0:0 10.161.10.49. The other one, eth1 is on a private network, 10.20.30.0. I want to use DNAT to allow test engineers to ssh into the machines in the web farm.

Re: [Shorewall-users] DNAT Issue

2008-10-01 Thread Rob Hicks
Thanks Martin! -Original Message- From: Martin Leben [mailto:[EMAIL PROTECTED] Sent: Wednesday, October 01, 2008 2:54 PM To: shorewall-users@lists.sourceforge.net Subject: Re: [Shorewall-users] DNAT Issue Rob Hicks wrote: Hi. Hi, The test lab firewall has two NICS. One (eth0) has

Re: [Shorewall-users] Dnat Issue - port 7025

2008-04-08 Thread Christian V R Lopes
My 2 cents, If your problem can't be solved with DNS and you really need it you can: 1 - put 'routeback' on interfaces to your dmz 2 - put a rule like (see the last parameter): DNATdmz dmz:10.0.1.100 tcp 7025 - 200.119.222.122 Fabricio Vargas wrote: Hi guys I have a problem so

Re: [Shorewall-users] Dnat Issue - port 7025

2008-04-08 Thread Fabricio Vargas
Thanks to everybody El mar, 08-04-2008 a las 09:04 -0300, Christian V R Lopes escribió: My 2 cents, If your problem can't be solved with DNS and you really need it you can: 1 - put 'routeback' on interfaces to your dmz 2 - put a rule like (see the last parameter): DNAT dmz

[Shorewall-users] Dnat Issue - port 7025

2008-04-07 Thread Fabricio Vargas
Hi guys I have a problem so i hope this list can help me. I have one public IP 200.119.222.122 (Shorewall) and a DMZ 10.0.1.100/24 (zimbra mail is running there) the problem is one service in dmz:10.0.1.100 is trying to connect fw:200.119.222.122 port 7025 because the service thinks it is the

Re: [Shorewall-users] Dnat Issue - port 7025

2008-04-07 Thread Roberto C . Sánchez
On Mon, Apr 07, 2008 at 04:26:48PM -0400, Fabricio Vargas wrote: Hi guys I have a problem so i hope this list can help me. I have one public IP 200.119.222.122 (Shorewall) and a DMZ 10.0.1.100/24 (zimbra mail is running there) the problem is one service in dmz:10.0.1.100 is trying to

Re: [Shorewall-users] Dnat Issue - port 7025

2008-04-07 Thread Andrew Suffield
On Mon, Apr 07, 2008 at 04:54:01PM -0400, Roberto C. S?nchez wrote: Now, if you decide that you don't want to do that, then you can follow the instructions for FAQ 2 for a different solution. I was thinking FAQ 1d... and then I look more closely, and 1d and 2b appear to be duplicates (except

Re: [Shorewall-users] Dnat Issue - port 7025

2008-04-07 Thread Tom Eastep
Andrew Suffield wrote: On Mon, Apr 07, 2008 at 04:54:01PM -0400, Roberto C. S?nchez wrote: Now, if you decide that you don't want to do that, then you can follow the instructions for FAQ 2 for a different solution. I was thinking FAQ 1d... and then I look more closely, and 1d and 2b appear to

Re: [Shorewall-users] Dnat Issue - port 7025

2008-04-07 Thread Tom Eastep
Tom Eastep wrote: Andrew Suffield wrote: I was thinking FAQ 1d... and then I look more closely, and 1d and 2b appear to be duplicates (except both have a comment or two that the other lacks). Weird. I cloned one from the other some time back when people were having problems finding the