Hi Tom! On 28/03/2014 19:36, Tom Eastep wrote: > On 3/28/2014 9:41 AM, Angela Williams wrote: >> Hi Tom! >> >> On 28/03/2014 18:02, Tom Eastep wrote: >>> On 3/28/2014 1:10 AM, Angela Williams wrote: >>>> Hi! >>>> >>>> On 27/03/2014 20:54, Tom Eastep wrote: >>>>> On 3/27/2014 10:54 AM, Angela Williams wrote: >>>>>> Hi Tom! >>>>>> >>>>>> On 27/03/2014 19:02, Tom Eastep wrote: >>>>>>> On 3/27/2014 8:53 AM, Angela Williams wrote: >>>>>>>> Hi All! >>>>>>>> I've no hit the same problem I hit quite some time back in trying to >>>>>>>> replace a rather limited script based iptables rule generator. Now I >>>>>>>> have no option really. The customer now has add a nice new 5M fibre >>>>>>>> connection to supplement the existing 1< leased line as well as an adsl >>>>>>>> link that is only for emergencies! >>>>>>>> >>>>>>>> Okay! The Problem! There are a few staff members the need to use a >>>>>>>> standard M$ PPiP vpn to connect to their biggest and almost only >>>>>>>> customers tracking system. I know the ideal is to set it up on the >>>>>>>> firewall but that will be a future project! Right now I need to get it >>>>>>>> working! I ran a tcpdump on the old script based system and the tcp >>>>>>>> 1723 >>>>>>>> and GRE packets just hapily fly back and forth! >>>>>>>> Stopped the old service and started shorewall. Another tcpdump showed >>>>>>>> no >>>>>>>> GRE packets being masq'd out. I can rule out anything with the kernel >>>>>>>> as >>>>>>>> that is the same for both firewall generators! >>>>>>>> >>>>>>>> Maybe it's just me misreading or misunderstanding the docs! >>>>>>>> Or maybe I just need my bum kicked! >>>>>>>> >>>>>>>> I have bziped up the shorewall dump and it is attached as >>>>>>>> ross.dump.bz2/ >>>>>>> >>>>>>> Hi Ang, >>>>>>> >>>>>>> Unfortunately, this dump shows no active connections using tcp port 1723 >>>>>>> or GRE. Can you capture one that demonstrates the issue? >>>>>> >>>>>> Me's just a bit flustered! Not thinking straight! >>>>>> >>>>>> This might just be a tad better! ross1.dump.bz2 attached! >>>>> >>>>> It doesn't look as though you have any of the helpers enabled. Try >>>>> setting AUTOHELPERS=Yes in shorewall.conf. >>>> >>>> The pptp and gre helpers are built into the kernel. The old script >>>> generated rirewall works just fine. >>>> In the meantime I'm going to get pptp setup on the server. At leastthe >>>> customer almost completely at 1239 today so I have time to test and not >>>> affect the staff! >>> >>> What is the setting of /proc/sys/net/netfilter/nf_conntrack_helper? >> >> It's set to 1 >> >> I do remember reading so time back about needing the pptp and gre >> helpers as modules and not in the kernel! >> Any thoughts as that would make your latest email valid! > > The behavior that I described is independent of whether your kernel is > modularized or not.
And I learnt a bit more! I do have AUTOHELPERS=Yes in the shorewall.conf file because I have the ones required compiled into the kernel. Ang -- Angela Williams angierfw at gmail dot com Linux/Networking Hacker Blog http://angierfw.wordpress.com Smile! Yeshua Loves You! ------------------------------------------------------------------------------ _______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
