Hi Tom!

On 28/03/2014 19:36, Tom Eastep wrote:
> On 3/28/2014 9:41 AM, Angela Williams wrote:
>> Hi Tom!
>>
>> On 28/03/2014 18:02, Tom Eastep wrote:
>>> On 3/28/2014 1:10 AM, Angela Williams wrote:
>>>> Hi!
>>>>
>>>> On 27/03/2014 20:54, Tom Eastep wrote:
>>>>> On 3/27/2014 10:54 AM, Angela Williams wrote:
>>>>>> Hi Tom!
>>>>>>
>>>>>> On 27/03/2014 19:02, Tom Eastep wrote:
>>>>>>> On 3/27/2014 8:53 AM, Angela Williams wrote:
>>>>>>>> Hi All!
>>>>>>>> I've no hit the same problem I hit quite some time back in trying to
>>>>>>>> replace a rather limited script based iptables rule generator. Now I
>>>>>>>> have no option really. The customer now has add a nice new 5M fibre
>>>>>>>> connection to supplement the existing 1< leased line as well as an adsl
>>>>>>>> link that is only for emergencies!
>>>>>>>>
>>>>>>>> Okay! The Problem! There are a few staff members the need to use a
>>>>>>>> standard M$ PPiP vpn to connect to their biggest and almost only
>>>>>>>> customers tracking system. I know the ideal is to set it up on the
>>>>>>>> firewall but that will be a future project!  Right now I need to get it
>>>>>>>> working! I ran a tcpdump on the old script based system and the tcp 
>>>>>>>> 1723
>>>>>>>> and GRE  packets just hapily fly back and forth!
>>>>>>>> Stopped the old service and started shorewall. Another tcpdump showed 
>>>>>>>> no
>>>>>>>> GRE packets being masq'd out. I can rule out anything with the kernel 
>>>>>>>> as
>>>>>>>> that is the same for both firewall generators!
>>>>>>>>
>>>>>>>> Maybe it's just me misreading or misunderstanding the docs!
>>>>>>>> Or maybe I just need my bum kicked!
>>>>>>>>
>>>>>>>> I have bziped up the shorewall dump and it is attached as 
>>>>>>>> ross.dump.bz2/
>>>>>>>
>>>>>>> Hi Ang,
>>>>>>>
>>>>>>> Unfortunately, this dump shows no active connections using tcp port 1723
>>>>>>> or GRE. Can you capture one that demonstrates the issue?
>>>>>>
>>>>>> Me's just a bit flustered! Not thinking straight!
>>>>>>
>>>>>> This might just be a tad better! ross1.dump.bz2 attached!
>>>>>
>>>>> It doesn't look as though you have any of the helpers enabled. Try
>>>>> setting AUTOHELPERS=Yes in shorewall.conf.
>>>>
>>>> The pptp and gre helpers are built into the kernel. The old script
>>>> generated rirewall works just fine.
>>>> In the meantime I'm going to get pptp setup on the server. At leastthe
>>>> customer almost completely at 1239 today so I have time to test and not
>>>> affect the staff!
>>>
>>> What is the setting of /proc/sys/net/netfilter/nf_conntrack_helper?
>>
>> It's set to 1
>>
>> I do remember reading so time back about needing the pptp and gre
>> helpers as modules and not in the kernel!
>> Any thoughts as that would make your latest email valid!
>
> The behavior that I described is independent of whether your kernel is
> modularized or not.

And I learnt a bit more!

I do have AUTOHELPERS=Yes in the shorewall.conf file because I have the 
ones required compiled into the kernel.

Ang

-- 
Angela Williams
angierfw at gmail dot com
Linux/Networking Hacker
Blog http://angierfw.wordpress.com

Smile! Yeshua Loves You!


------------------------------------------------------------------------------
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to