[Shorewall-users] OpenVPN server with Shorewall not working

2015-03-25 Thread Thomas Winkler
Hello,   I really like Shorewall ! Thanks for this piece of software ! I am using Shorewall on an ARM single computer with two NICs running on Debian 7.8 which runs perfectly.     I installed the OpenVPN server on that single computer board and trying to get OpenVPN server running together with S

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-25 Thread Hesham Ahmed
I don't use tunnels file anymore since everything it does can be done with rules or other files. I understand you're running the OpenVPN Server on the same machine as Shorewall, in that case add the following to your rules file and then try connecting: OpenVPN/ACCEPTnet$FW Regards, Hesha

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-25 Thread Robert K Coffman Jr. -Info From Data Corp.
On my OpenVPN server, I'm using openvpn rather than openvpnclient in the tunnels file. - Bob -- Dive into the World of Parallel Programming The Go Parallel Website, sponsored by Intel and developed in partnership with S

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-25 Thread matt darfeuille
If shorewall is on the same box as the openvpn server you need at least to change "openvpnclient" to "openvpnserver". Depending on your shorewall version the rules file is more straightforward! -Matt On 25 Mar 2015 at 17:54, Thomas Winkler wrote: > Hello, >   > I really like Shorewall ! Thank

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-26 Thread Thomas Winkler
ing:   OpenVPN/ACCEPT    net    $FW   Regards,   Hesham Ahmed      Gesendet: Mittwoch, 25. März 2015 um 18:56 Uhr Von: "matt darfeuille" An: "Shorewall Users" Betreff: Re: [Shorewall-users] OpenVPN server with Shorewall not working If shorewall is on the same box as the openvp

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-26 Thread Angela Williams
assume that the openvpn server runs on your firewall that runs shorewall! I used grep vpn on one of my customer firewalls with openvpn on the firewall > > > Regards, > > > Thomas > > > > > > Gesendet: Mittwoch, 25. März 2015 um 19:24 Uhr > Von: "Hesham Ah

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-26 Thread Thomas Winkler
dport 1194 -j ACCEPT iptables -A INPUT -i tun0 -j ACCEPT iptables -A FORWARD -i tun0 -j ACCEPT Regards, Thomas     Gesendet: Donnerstag, 26. März 2015 um 15:32 Uhr Von: "Angela Williams" An: "Shorewall Users" Betreff: Re: [Shorewall-users] OpenVPN server with Shorewal

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-26 Thread Robert K Coffman Jr. -Info From Data Corp.
On 3/26/2015 12:32 PM, Thomas Winkler wrote: > I used your settings but still it doesn't work when I run shorewall. If the client can't connect, which is what I assume you mean when you say "it doesn't work" then you should have something in the shorewall log that will give you a clue as to why

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-26 Thread Angela Williams
Hi Thomas! On 26/03/2015 18:32, Thomas Winkler wrote: > Hello Angela, > > Yes, openvpn server and shorewall run on the same ARM embedded system ( > Debian 7.8). > > Shorewall version : 4.5.5.3 > Linux Kernel 3.18 > > > I used your settings but still it doesn't work when I run shorewall. >

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-26 Thread Hesham Ahmed
woch, 25. März 2015 um 19:24 Uhr > > Von: "Hesham Ahmed" > > An: "Shorewall Users" > > Betreff: Re: [Shorewall-users] OpenVPN server with Shorewall not working > > > > I don't use tunnels file anymore since everything it does can be done >

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-27 Thread Thomas Winkler
uot; Betreff: Re: [Shorewall-users] OpenVPN server with Shorewall not working On 3/26/2015 12:32 PM, Thomas Winkler wrote: > I used your settings but still it doesn't work when I run shorewall. If the client can't connect, which is what I assume you mean when you say "it doesn't

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-27 Thread Thomas Winkler
also doesn't generate the shorewall.log file, I begin to believe that my Debian Wheezy ARM shorewall version might have some errors ?   Regards, Thomas   Gesendet: Donnerstag, 26. März 2015 um 23:20 Uhr Von: "Hesham Ahmed" An: "Shorewall Users" Betreff: Re: [Shorewall-us

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-27 Thread matt darfeuille
;s latest tips). >   > I attached my shorewall.conf >   >   > > > >   >   > > Gesendet: Donnerstag, 26. März 2015 um 18:01 Uhr > Von: "Robert K Coffman Jr. -Info From Data Corp." > > An: "Shorewall Users" > Betreff: Re: [Shorewall-users] Open

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-27 Thread Angela Williams
Hi Thomas On 27/03/2015 15:14, Thomas Winkler wrote: > Hello, > > @ Ahmed : I used your latest rule but still it doesn't work. > > This is the iptables LOG output after running shorewall with your rule added : > > INPUT:DROP:IN=eth0 OUT= MAC=XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX > SRC=192.

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-27 Thread Tom Eastep
On 3/27/2015 6:14 AM, Thomas Winkler wrote: > Hello, > > @ Ahmed : I used your latest rule but still it doesn't work. > > This is the iptables LOG output after running shorewall with your rule added : > > INPUT:DROP:IN=eth0 OUT= MAC=XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX > SRC=192.168.70.85

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-27 Thread Stephen Williams
sorry to hear you have been under the weather. hope you get well soon! On 3/27/2015 1:17 PM, Tom Eastep wrote: On 3/27/2015 6:14 AM, Thomas Winkler wrote: Hello, @ Ahmed : I used your latest rule but still it doesn't work. This is the iptables LOG output after running shorewall with your rul

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-30 Thread Thomas Winkler
: "Tom Eastep" An: shorewall-users@lists.sourceforge.net Betreff: Re: [Shorewall-users] OpenVPN server with Shorewall not working On 3/27/2015 6:14 AM, Thomas Winkler wrote: > Hello, > > @ Ahmed : I used your latest rule but still it doesn't work. > > This is the iptab

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-30 Thread Tom Eastep
On 3/30/2015 11:07 AM, Thomas Winkler wrote: > Hello, > > I ran the shorewall debug start 2>/tmp/trace command and this is the output > of the trace file : > > WARNING: Using an interface as the masq SOURCE requires the interface to be > up and configured when Shorewall starts/restarts /etc/sho

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-31 Thread Thomas Winkler
20:52 Uhr Von: "Tom Eastep" An: shorewall-users@lists.sourceforge.net Betreff: Re: [Shorewall-users] OpenVPN server with Shorewall not working On 3/30/2015 11:07 AM, Thomas Winkler wrote: > Hello, > > I ran the shorewall debug start 2>/tmp/trace command and this is the

Re: [Shorewall-users] OpenVPN server with Shorewall not working

2015-03-31 Thread Tom Eastep
On 3/31/2015 2:42 AM, Thomas Winkler wrote: > Thanks Tom ! > > > CLAMPMSS option in shorewall.conf caused the error. My Linux kernel on Debian > 7.8 ARM didn't support that option. > > I set CLAMPMSS=No and now Shorewall works perfectly with my OpenVPN server. > > > You solved my issue. Go