Miguel A. Velasco wrote:

>         I have tried running shorewall with this config but I
>         haven´t internet access. Even I can´t ping from the
>         firewall to 10.10.90.3 or 10.10.100.3 ....
>         ¿Any idea?

Yes -- just forget my suggestion.


> 
>     At this point what do you suggest me? I mean: as you say the
>     problem is not in shorewall config and isn´t on the windows
>     machine (pptp client) because I am able to connect this Server
>     directly to pptp server, avoiding shorewall firewall

I keep trying to tell you that you are avoiding *double NAT* when you
connect directly. I suspect that is the problem and it may not be
solvable; I don't know. The trace log you sent (which STILL DIDN'T USE
THE -n OPTION) shows both TCP and GRE traffic flowing in both
directions. So there is nothing more that I know of that you can expect
the firewall to do.

>     (connecting through the adsl router ...).
>     Then, when you say it´s a PPTP issue what do you exactly
>     refer?.

See above. You need to get help from PPTP experts, not Firewall experts.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Download Intel® Parallel Studio Eval
Try the new software tools for yourself. Speed compiling, find bugs
proactively, and fine-tune applications for parallel performance.
See why Intel Parallel Studio got high marks during beta.
http://p.sf.net/sfu/intel-sw-dev
_______________________________________________
Shorewall-users mailing list
Shorewall-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to