-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Simon Buckner wrote:

> I have setup a IPSEC VPN using Openswan to connect a Draytek router
> to a CentOS 5.2/Shorewall 4.2.9 firewall.  The VPN establishes OK but
> I’m getting a problem with packets from the left hand subnet getting 
> masqueraded rather than routed down the IPSEC VPN as though they were
>  going out onto the net.

This is almost always an IPSEC configuration problem that has nothing to
do with Shorewall.

> I’ve spent the last day searching Google

It would have likely been profitable to have spent part of that time
reading http://www.shorewall.net/IPSEC-2.6.html.

> and so far I’ve hit a brick wall and was hoping someone could help
> point me in the right direction.

Temporarily 'shorewall clear' then try to establish a connection from
the 'left subnet' through the VPN. Does it work? I'm guessing not.

(be sure to 'shorewall start' after the test).

Unless the connection suddenly starts working, then the immediate
problem has nothing to do with Shorewall. If it does start working, then
the above URL will undoubtedly be useful.

> 
> 
> 
> If anyone thinks they can help let me know what info you need and
> I’ll be happy to provide it.

For us to be of any help, we need the output of 'shorewall dump'
collected exactly as described at
http://www.shorewall.net/support.htm#Guidelines.

- -Tom
- --
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (GNU/Linux)
Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org

iEYEARECAAYFAkqDG0EACgkQO/MAbZfjDLKMAACfQpjypMPCLESo04NGk6MJqmZ1
/94An0vUW5YYkwySu6g1RCZhFSBWvk2N
=yRkg
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to