Re: [Shorewall-users] stoppedrules file in 4.5.4 (/etc/shorewall/routestopped)

2013-08-29 Thread Thomas Harold
On 8/28/2013 8:43 PM, Tom Eastep wrote: On 8/28/2013 4:43 PM, Tom Eastep wrote: On 8/28/2013 3:44 PM, Thomas Harold wrote: Shorewall 4.5.4 Dump at fw2-sec - Wed Aug 28 18:31:52 EDT 2013 - Support for /etc/shorewall/stoppedrules wasn't added until Shorewall 4.5.8. In 4.5.8,

Re: [Shorewall-users] stoppedrules file in 4.5.4 (/etc/shorewall/routestopped)

2013-08-29 Thread Tom Eastep
On 8/29/2013 6:01 AM, Thomas Harold wrote: On 8/28/2013 8:43 PM, Tom Eastep wrote: On 8/28/2013 4:43 PM, Tom Eastep wrote: On 8/28/2013 3:44 PM, Thomas Harold wrote: Shorewall 4.5.4 Dump at fw2-sec - Wed Aug 28 18:31:52 EDT 2013 - Support for /etc/shorewall/stoppedrules

Re: [Shorewall-users] stoppedrules file in 4.5.4 (/etc/shorewall/routestopped)

2013-08-29 Thread Thomas Harold
On 8/29/2013 9:01 AM, Thomas Harold wrote: /etc/shorewall/routestopped bond0 - - icmp bond0 - - tcp 22 bond0 - - udp 123 bond0 -

Re: [Shorewall-users] stoppedrules file in 4.5.4

2013-08-28 Thread Tom Eastep
On 8/27/2013 2:02 PM, Thomas Harold wrote: We have a bonded pair of ethernet ports (eth0+eth1 - bond0) defined in /etc/shorewall/interfaces as: loc bond0 The /etc/shorewall/zones is: fw firewall loc ipv4 net ipv4 When shorewall is stopped, I want to still allow

Re: [Shorewall-users] stoppedrules file in 4.5.4

2013-08-28 Thread Thomas Harold
On 8/28/2013 12:41 PM, Tom Eastep wrote: On 8/27/2013 2:02 PM, Thomas Harold wrote: We have a bonded pair of ethernet ports (eth0+eth1 - bond0) defined in /etc/shorewall/interfaces as: loc bond0 The /etc/shorewall/zones is: fw firewall loc ipv4 net ipv4 When shorewall is

Re: [Shorewall-users] stoppedrules file in 4.5.4

2013-08-28 Thread Tom Eastep
On 8/28/2013 3:44 PM, Thomas Harold wrote: So a little background here: - We're running a multi-ISP configuration, a cable modem (wancbl) and a T1 line (want1). Cable modem is the primary, T1 is the fallback. - Internal connection to the LAN is a bonded pair (bond0) of ethernet

Re: [Shorewall-users] stoppedrules file in 4.5.4

2013-08-28 Thread Tom Eastep
On 8/28/2013 4:43 PM, Tom Eastep wrote: On 8/28/2013 3:44 PM, Thomas Harold wrote: So a little background here: - We're running a multi-ISP configuration, a cable modem (wancbl) and a T1 line (want1). Cable modem is the primary, T1 is the fallback. - Internal connection to the LAN is a

[Shorewall-users] stoppedrules file in 4.5.4

2013-08-27 Thread Thomas Harold
We have a bonded pair of ethernet ports (eth0+eth1 - bond0) defined in /etc/shorewall/interfaces as: loc bond0 The /etc/shorewall/zones is: fw firewall loc ipv4 net ipv4 When shorewall is stopped, I want to still allow traffic from the local zone (bond0) to the firewall to open