On 3/28/2014 9:02 AM, Tom Eastep wrote: > On 3/28/2014 1:10 AM, Angela Williams wrote: >> Hi! >> >> On 27/03/2014 20:54, Tom Eastep wrote: >>> On 3/27/2014 10:54 AM, Angela Williams wrote: >>>> Hi Tom! >>>> >>>> On 27/03/2014 19:02, Tom Eastep wrote: >>>>> On 3/27/2014 8:53 AM, Angela Williams wrote: >>>>>> Hi All! >>>>>> I've no hit the same problem I hit quite some time back in trying to >>>>>> replace a rather limited script based iptables rule generator. Now I >>>>>> have no option really. The customer now has add a nice new 5M fibre >>>>>> connection to supplement the existing 1< leased line as well as an adsl >>>>>> link that is only for emergencies! >>>>>> >>>>>> Okay! The Problem! There are a few staff members the need to use a >>>>>> standard M$ PPiP vpn to connect to their biggest and almost only >>>>>> customers tracking system. I know the ideal is to set it up on the >>>>>> firewall but that will be a future project! Right now I need to get it >>>>>> working! I ran a tcpdump on the old script based system and the tcp 1723 >>>>>> and GRE packets just hapily fly back and forth! >>>>>> Stopped the old service and started shorewall. Another tcpdump showed no >>>>>> GRE packets being masq'd out. I can rule out anything with the kernel as >>>>>> that is the same for both firewall generators! >>>>>> >>>>>> Maybe it's just me misreading or misunderstanding the docs! >>>>>> Or maybe I just need my bum kicked! >>>>>> >>>>>> I have bziped up the shorewall dump and it is attached as ross.dump.bz2/ >>>>> >>>>> Hi Ang, >>>>> >>>>> Unfortunately, this dump shows no active connections using tcp port 1723 >>>>> or GRE. Can you capture one that demonstrates the issue? >>>> >>>> Me's just a bit flustered! Not thinking straight! >>>> >>>> This might just be a tad better! ross1.dump.bz2 attached! >>> >>> It doesn't look as though you have any of the helpers enabled. Try >>> setting AUTOHELPERS=Yes in shorewall.conf. >> >> The pptp and gre helpers are built into the kernel. The old script >> generated rirewall works just fine. >> In the meantime I'm going to get pptp setup on the server. At leastthe >> customer almost completely at 1239 today so I have time to test and not >> affect the staff! > > What is the setting of /proc/sys/net/netfilter/nf_conntrack_helper?
You are running a kernel >= 3.5. So with your script running (assuming that you 'shorewall clear' before invoking your script), it will be set to 1. While Shorewall is running, it will be set to 0 and the helpers must be enabled by one of the following methods: - You can enable all available helpers by setting AUTOHELPERS=Yes in shorewall.conf. - You can enable individual helpers using the HELPERS option in shorewall.conf. - You can add your own rules in /etc/shorewall/conntrack. -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
