[Shorewall-users] Websites Are Down!

2019-01-12 Thread C. Cook
... and can't get up! [Sat Jan 12 11:56:22 2019] FORWARD REJECT IN=eth0 OUT=eth0 MAC=00:1f:5b:23:51:f2:f6:b5:2f:a2:db:8e:08:00 SRC=5.158.83.30 DST=10.1.1.30 LEN=48 TOS=0x00 PREC=0x00 TTL=42 ID=47070 DF PROTO=TCP SPT=60896 DPT=443 WINDOW=29200 RES=0x00 SYN URGP=0 OPT (020405B401030307) [Sat Jan 12

Re: [Shorewall-users] Websites Are Down!

2019-01-12 Thread Roberto C . Sánchez
On Sat, Jan 12, 2019 at 12:33:48PM -0800, C. Cook wrote: >... and can't get up! > >[Sat Jan 12 11:56:22 2019] FORWARD REJECT IN=eth0 OUT=eth0 Have you specified routeback for eth0 in interfaces? Regards, -Roberto -- Rober

Re: [Shorewall-users] Websites Are Down!

2019-01-12 Thread C. Cook
On 1/12/19 12:37 PM, Roberto C. Sánchez wrote: > On Sat, Jan 12, 2019 at 12:33:48PM -0800, C. Cook wrote: >>... and can't get up! >> >>[Sat Jan 12 11:56:22 2019] FORWARD REJECT IN=eth0 OUT=eth0 > > > Have you specified routeba

Re: [Shorewall-users] Websites Are Down!

2019-01-12 Thread C. Cook
On 1/12/19 12:45 PM, C. Cook wrote: > > > On 1/12/19 12:37 PM, Roberto C. Sánchez wrote: >> On Sat, Jan 12, 2019 at 12:33:48PM -0800, C. Cook wrote: >>>... and can't get up! >>> >>>[Sat Jan 12 11:56:22 2019] FORWARD REJECT IN=eth0 OUT=eth0 >>

Re: [Shorewall-users] Websites Are Down!

2019-01-12 Thread C. Cook
On 1/12/19 1:10 PM, C. Cook wrote: > > > On 1/12/19 12:45 PM, C. Cook wrote: >> >> >> On 1/12/19 12:37 PM, Roberto C. Sánchez wrote: >>> On Sat, Jan 12, 2019 at 12:33:48PM -0800, C. Cook wrote: ... and can't get up! [Sat Jan 12 11:56:22 2019] FORWARD REJECT IN=eth0 OUT=eth0 >>

Re: [Shorewall-users] Websites Are Down!

2019-01-12 Thread C. Cook
On 1/12/19 1:24 PM, C. Cook wrote: > > > On 1/12/19 1:10 PM, C. Cook wrote: >> >> >> On 1/12/19 12:45 PM, C. Cook wrote: >>> >>> >>> On 1/12/19 12:37 PM, Roberto C. Sánchez wrote: On Sat, Jan 12, 2019 at 12:33:48PM -0800, C. Cook wrote: >... and can't get up! > >[Sat Jan 1

Re: [Shorewall-users] Websites Are Down!

2019-01-13 Thread Tom Eastep
On 1/12/19 2:08 PM, C. Cook wrote: > > On 1/12/19 1:24 PM, C. Cook wrote: >> >> >> On 1/12/19 1:10 PM, C. Cook wrote: >>> >>> >>> On 1/12/19 12:45 PM, C. Cook wrote: On 1/12/19 12:37 PM, Roberto C. Sánchez wrote: > On Sat, Jan 12, 2019 at 12:33:48PM -0800, C. Cook wrote: >>

Re: [Shorewall-users] Websites Are Down!

2019-01-13 Thread C. Cook
> What you are trying to do *will never work*. You are accepting web > connections on the public IP address on the Shorewall router, port > forwarding them to the web server who is trying to reply out of the WG > server. There are two problems with this idea: > > a) The WG server can't reverse the

Re: [Shorewall-users] Websites Are Down!

2019-01-13 Thread Tom Eastep
On 1/13/19 11:21 AM, C. Cook wrote: > >> What you are trying to do *will never work*. You are accepting web >> connections on the public IP address on the Shorewall router, port >> forwarding them to the web server who is trying to reply out of the WG >> server. There are two problems with this id

Re: [Shorewall-users] Websites Are Down!

2019-01-13 Thread C. Cook
On 1/13/19 11:24 AM, Tom Eastep wrote: > On 1/13/19 11:21 AM, C. Cook wrote: >>> What you are trying to do *will never work*. You are accepting web >>> connections on the public IP address on the Shorewall router, port >>> forwarding them to the web server who is trying to reply out of the WG >>> s