[Shorewall-users] Shorewall rejects NTP requests

2017-05-11 Thread Sven Kobow
Hi, I have setup my shorewall firewall as demonstrated in the two interface sample. So far it is working okay. I only have the problem that it is not possible to do NTP requests to public NTP servers and I can see that these requests are rejected by shorewall as there are log entries. I tried addi

Re: [Shorewall-users] Shorewall rejects NTP requests

2017-05-11 Thread Roberto C . Sánchez
On Thu, May 11, 2017 at 03:29:06PM +0200, Sven Kobow wrote: >Hi, >I have setup my shorewall firewall as demonstrated in the two interface >sample. So far it is working okay. I only have the problem that it is not >possible to do NTP requests to public NTP servers and I can see that

Re: [Shorewall-users] Shorewall rejects NTP requests

2017-05-12 Thread Sven Kobow
Hi Roberto, here is the output: [BEGIN] Shorewall 5.0.4 Dump at firewall.local - Do 11. Mai 21:15:07 CEST 2017 Shorewall is running State:Started (Mi 10. Mai 22:51:44 CEST 2017) from /etc/shorewall/ (/var/lib/shorewall/firewall compiled by Shorewall version 5.0.4) Counters reset Mi 10. Mai 22:5

Re: [Shorewall-users] Shorewall rejects NTP requests

2017-05-12 Thread Roberto C . Sánchez
[SNIP] > Chain loc-net (1 references) > pkts bytes target prot opt in out source > destination > 11685 3316K ACCEPT all -- * * 0.0.0.0/0 > 0.0.0.0/0ctstate RELATED,ESTABLISHED > 21402 1627K ACCEPT udp -- * * 0.0.0.0/0 > 0.0.

Re: [Shorewall-users] Shorewall rejects NTP requests

2017-05-12 Thread Paul Gear
On 12/05/17 21:15, Roberto C. Sánchez wrote: > > [SNIP] >> Chain loc-net (1 references) >> pkts bytes target prot opt in out source >> destination >> 11685 3316K ACCEPT all -- * * 0.0.0.0/0 >> 0.0.0.0/0ctstate RELATED,ESTABLISHED >> 21402 16

Re: [Shorewall-users] Shorewall rejects NTP requests

2017-05-13 Thread Sven Kobow
Problem solved! Shorewall was not the reason. The reason was my router filtering UDP requests. I did not know about these filters... and some log entries were missleading me. Sorry for the noise and thanks for your help! Best Sven > Am 12.05.2017 um 13:53 schrieb Paul Gear : > >> On 12/05/17