Hi Tom On 28/03/2014 20:04, Angela Williams wrote: > Hi Tom! > > On 28/03/2014 19:36, Tom Eastep wrote: >> On 3/28/2014 9:41 AM, Angela Williams wrote: >>> Hi Tom! >>> >>> On 28/03/2014 18:02, Tom Eastep wrote: >>>> On 3/28/2014 1:10 AM, Angela Williams wrote: >>>>> Hi! >>>>> >>>>> On 27/03/2014 20:54, Tom Eastep wrote: >>>>>> On 3/27/2014 10:54 AM, Angela Williams wrote: >>>>>>> Hi Tom! >>>>>>> >>>>>>> On 27/03/2014 19:02, Tom Eastep wrote: >>>>>>>> On 3/27/2014 8:53 AM, Angela Williams wrote: >>>>>>>>> Hi All! >>>>>>>>> I've no hit the same problem I hit quite some time back in >>>>>>>>> trying to >>>>>>>>> replace a rather limited script based iptables rule generator. >>>>>>>>> Now I >>>>>>>>> have no option really. The customer now has add a nice new 5M >>>>>>>>> fibre >>>>>>>>> connection to supplement the existing 1< leased line as well as >>>>>>>>> an adsl >>>>>>>>> link that is only for emergencies! >>>>>>>>> >>>>>>>>> Okay! The Problem! There are a few staff members the need to use a >>>>>>>>> standard M$ PPiP vpn to connect to their biggest and almost only >>>>>>>>> customers tracking system. I know the ideal is to set it up on the >>>>>>>>> firewall but that will be a future project! Right now I need >>>>>>>>> to get it >>>>>>>>> working! I ran a tcpdump on the old script based system and the >>>>>>>>> tcp 1723 >>>>>>>>> and GRE packets just hapily fly back and forth! >>>>>>>>> Stopped the old service and started shorewall. Another tcpdump >>>>>>>>> showed no >>>>>>>>> GRE packets being masq'd out. I can rule out anything with the >>>>>>>>> kernel as >>>>>>>>> that is the same for both firewall generators! >>>>>>>>> >>>>>>>>> Maybe it's just me misreading or misunderstanding the docs! >>>>>>>>> Or maybe I just need my bum kicked! >>>>>>>>> >>>>>>>>> I have bziped up the shorewall dump and it is attached as >>>>>>>>> ross.dump.bz2/ >>>>>>>> >>>>>>>> Hi Ang, >>>>>>>> >>>>>>>> Unfortunately, this dump shows no active connections using tcp >>>>>>>> port 1723 >>>>>>>> or GRE. Can you capture one that demonstrates the issue? >>>>>>> >>>>>>> Me's just a bit flustered! Not thinking straight! >>>>>>> >>>>>>> This might just be a tad better! ross1.dump.bz2 attached! >>>>>> >>>>>> It doesn't look as though you have any of the helpers enabled. Try >>>>>> setting AUTOHELPERS=Yes in shorewall.conf. >>>>> >>>>> The pptp and gre helpers are built into the kernel. The old script >>>>> generated rirewall works just fine. >>>>> In the meantime I'm going to get pptp setup on the server. At leastthe >>>>> customer almost completely at 1239 today so I have time to test and >>>>> not >>>>> affect the staff! >>>> >>>> What is the setting of /proc/sys/net/netfilter/nf_conntrack_helper? >>> >>> It's set to 1 >>> >>> I do remember reading so time back about needing the pptp and gre >>> helpers as modules and not in the kernel! >>> Any thoughts as that would make your latest email valid! >> >> The behavior that I described is independent of whether your kernel is >> modularized or not. > > And I learnt a bit more! > > I do have AUTOHELPERS=Yes in the shorewall.conf file because I have the > ones required compiled into the kernel.
I shut down the old firewall and started shorewall and /proc/sys/net/netfilter/nf_conntrack_helper was set to 0 I tried to force it to 1 but maybe that not right! Ang -- Angela Williams angierfw at gmail dot com Linux/Networking Hacker Blog http://angierfw.wordpress.com Smile! Yeshua Loves You! ------------------------------------------------------------------------------ _______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
