[Shorewall-users] lsm configuration issues...

2013-09-10 Thread John Doe
Hi, I use shorewall-4.5.4 + lsm-0.143 and it does not seem to work as expected... When all providers are up, everything seems fine. When one goes down, lsm says "link down event"... and it seems ok but we then experience some problems such as a few unreachable sites, DNS problems... If I rem

Re: [Shorewall-users] lsm configuration issues...

2013-09-10 Thread Tom Eastep
On 09/10/2013 08:24 AM, John Doe wrote: > Hi, > > I use shorewall-4.5.4 + lsm-0.143 and it does not seem to work as expected... > When all providers are up, everything seems fine. > > When one goes down, lsm says "link down event"... and it seems > > ok but we then experience some problems suc

Re: [Shorewall-users] lsm configuration issues...

2013-09-12 Thread Thomas Harold
On 9/10/2013 11:24 AM, John Doe wrote: > > -- > /etc/lsm/lsm.conf > -- > > debug=8 > defaults { >name=defaults >checkip=127.0.0.1 >eventscript=/etc/lsm

Re: [Shorewall-users] lsm configuration issues...

2013-09-23 Thread John Doe
From: Tom Eastep > To: shorewall-users@lists.sourceforge.net > Cc: > Sent: Tuesday, September 10, 2013 6:34 PM > Subject: Re: [Shorewall-users] lsm configuration issues... > > On 09/10/2013 08:24 AM, John Doe wrote: >> Hi, >> >> I use shorewall-4.5.4 + ls

Re: [Shorewall-users] lsm configuration issues...

2013-09-23 Thread Tom Eastep
On 9/23/2013 3:05 AM, John Doe wrote: > > Finally found the time to test and... it still fails... > If I put the next hop, with the manual routes (which do work with a ping > test), > lsm will correctly detect the link down, but will never detect the link back > up (even if > I have no proble

Re: [Shorewall-users] lsm configuration issues...

2013-09-23 Thread John Doe
From: Tom Eastep > Rather than running ${VARDIR}/firewall, you can just run > ${SBINDIR}/shorewall (usually /sbin/shorewall or /usr/sbin/shorewall): > >     shorewall disable >     shorewall enable Thx, JD -- LIMITED

Re: [Shorewall-users] lsm configuration issues...

2013-09-27 Thread Tuomo Soini
On Thu, 12 Sep 2013 03:24:40 -0400 Thomas Harold wrote: > One pitfall that I found is that "status=1" is set to zero by default > in the stock /etc/lsm/lsm.conf file. That's not true. Default of status is 2 eg unknown. > The Shorewall scripts in the MultiISP document depend on LSM assuming > t