Pál Csányi wrote:
> 2007/8/2, Tom Eastep <[EMAIL PROTECTED]>:

>> Why are you specifying a range of IP addresses? Are you running 89 smtp
>> servers? You should only be specifying the IP address of the system where
>> exim is running (192.168.1.98).
> 
> Because my firewall run a dhcp server and give IP addresses for the subnet
> systems. How can I know in this case which IP adrress will be assigned to
> desktop machine?

You configure your DHCP server to always give the desktop the same IP
address (by specifying the desktop's MAC address in the configuration).
Almost 8 hours ago, Andrew Suffield told you that the rule was wrong and you
are still using it. You can leave it there for another 8 years and it still
won't work.

To repeat: The rule needs to specify the the address of the desktop and
*only* the address of the desktop.


> 
> 3.a. Yes, Shorewall Started Successfully.
> 3.b. Connection or Traffic Shaping Problem(s)?
> I think this is a Traffic Problem.
> 3.c. #/sbin/shorewall dump > /tmp/status.txt
> 3.d. Post attachment compressed with bzip2.
> 3.e. My public IP address is 212.200.112.79 with FQDN: csanyi-pal.info
> My firewall has 3 interfaces:
> eth0 - internet
> eth1 - localnet
> ppp0 - for the pptp VPN tunnel to my ISP.
> 
> I can't to send mail to mailing lists from my desktop box that is
> behind firewall, because the remote mailservers can't reach my exim4
> for communications (helo - ehlo).
> 
> This desktop box get dinamic IP address from the firewall, usually 
> 192.168.1.98

Again, that will never work.

> 
> I hope this help to solve my problem with your help.
> 

Fix your DHCP configuration and fix the DNAT rule and it will work.

That is assuming that the Exim server is listening on address 0.0.0.0 and
not 127.0.0.1 (many packages configure the server to listen only for local
traffic).

Use "netstat -tnap" to see which local IP address exim is bound to.

-Tom
-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ [EMAIL PROTECTED]
PGP Public Key   \ https://lists.shorewall.net/teastep.pgp.key

Attachment: signature.asc
Description: OpenPGP digital signature

-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >>  http://get.splunk.com/
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to