Hi Tom

On 28/03/2014 20:04, Angela Williams wrote:
> Hi Tom!
>
> On 28/03/2014 19:36, Tom Eastep wrote:
>> On 3/28/2014 9:41 AM, Angela Williams wrote:
>>> Hi Tom!
>>>
>>> On 28/03/2014 18:02, Tom Eastep wrote:
>>>> On 3/28/2014 1:10 AM, Angela Williams wrote:
>>>>> Hi!
>>>>>
>>>>> On 27/03/2014 20:54, Tom Eastep wrote:
>>>>>> On 3/27/2014 10:54 AM, Angela Williams wrote:
>>>>>>> Hi Tom!
>>>>>>>
>>>>>>> On 27/03/2014 19:02, Tom Eastep wrote:
>>>>>>>> On 3/27/2014 8:53 AM, Angela Williams wrote:
>>>>>>>>> Hi All!
>>>>>>>>> I've no hit the same problem I hit quite some time back in
>>>>>>>>> trying to
>>>>>>>>> replace a rather limited script based iptables rule generator.
>>>>>>>>> Now I
>>>>>>>>> have no option really. The customer now has add a nice new 5M
>>>>>>>>> fibre
>>>>>>>>> connection to supplement the existing 1< leased line as well as
>>>>>>>>> an adsl
>>>>>>>>> link that is only for emergencies!
>>>>>>>>>
>>>>>>>>> Okay! The Problem! There are a few staff members the need to use a
>>>>>>>>> standard M$ PPiP vpn to connect to their biggest and almost only
>>>>>>>>> customers tracking system. I know the ideal is to set it up on the
>>>>>>>>> firewall but that will be a future project!  Right now I need
>>>>>>>>> to get it
>>>>>>>>> working! I ran a tcpdump on the old script based system and the
>>>>>>>>> tcp 1723
>>>>>>>>> and GRE  packets just hapily fly back and forth!
>>>>>>>>> Stopped the old service and started shorewall. Another tcpdump
>>>>>>>>> showed no
>>>>>>>>> GRE packets being masq'd out. I can rule out anything with the
>>>>>>>>> kernel as
>>>>>>>>> that is the same for both firewall generators!
>>>>>>>>>
>>>>>>>>> Maybe it's just me misreading or misunderstanding the docs!
>>>>>>>>> Or maybe I just need my bum kicked!
>>>>>>>>>
>>>>>>>>> I have bziped up the shorewall dump and it is attached as
>>>>>>>>> ross.dump.bz2/
>>>>>>>>
>>>>>>>> Hi Ang,
>>>>>>>>
>>>>>>>> Unfortunately, this dump shows no active connections using tcp
>>>>>>>> port 1723
>>>>>>>> or GRE. Can you capture one that demonstrates the issue?
>>>>>>>
>>>>>>> Me's just a bit flustered! Not thinking straight!
>>>>>>>
>>>>>>> This might just be a tad better! ross1.dump.bz2 attached!
>>>>>>
>>>>>> It doesn't look as though you have any of the helpers enabled. Try
>>>>>> setting AUTOHELPERS=Yes in shorewall.conf.
>>>>>
>>>>> The pptp and gre helpers are built into the kernel. The old script
>>>>> generated rirewall works just fine.
>>>>> In the meantime I'm going to get pptp setup on the server. At leastthe
>>>>> customer almost completely at 1239 today so I have time to test and
>>>>> not
>>>>> affect the staff!
>>>>
>>>> What is the setting of /proc/sys/net/netfilter/nf_conntrack_helper?
>>>
>>> It's set to 1
>>>
>>> I do remember reading so time back about needing the pptp and gre
>>> helpers as modules and not in the kernel!
>>> Any thoughts as that would make your latest email valid!
>>
>> The behavior that I described is independent of whether your kernel is
>> modularized or not.
>
> And I learnt a bit more!
>
> I do have AUTOHELPERS=Yes in the shorewall.conf file because I have the
> ones required compiled into the kernel.

I shut down the old firewall and started shorewall and 
/proc/sys/net/netfilter/nf_conntrack_helper was set to 0
I tried to force it to 1 but maybe that not right!

Ang


-- 
Angela Williams
angierfw at gmail dot com
Linux/Networking Hacker
Blog http://angierfw.wordpress.com

Smile! Yeshua Loves You!


------------------------------------------------------------------------------
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to