On 3/28/2014 9:02 AM, Tom Eastep wrote:
> On 3/28/2014 1:10 AM, Angela Williams wrote:
>> Hi!
>>
>> On 27/03/2014 20:54, Tom Eastep wrote:
>>> On 3/27/2014 10:54 AM, Angela Williams wrote:
>>>> Hi Tom!
>>>>
>>>> On 27/03/2014 19:02, Tom Eastep wrote:
>>>>> On 3/27/2014 8:53 AM, Angela Williams wrote:
>>>>>> Hi All!
>>>>>> I've no hit the same problem I hit quite some time back in trying to
>>>>>> replace a rather limited script based iptables rule generator. Now I
>>>>>> have no option really. The customer now has add a nice new 5M fibre
>>>>>> connection to supplement the existing 1< leased line as well as an adsl
>>>>>> link that is only for emergencies!
>>>>>>
>>>>>> Okay! The Problem! There are a few staff members the need to use a
>>>>>> standard M$ PPiP vpn to connect to their biggest and almost only
>>>>>> customers tracking system. I know the ideal is to set it up on the
>>>>>> firewall but that will be a future project!  Right now I need to get it
>>>>>> working! I ran a tcpdump on the old script based system and the tcp 1723
>>>>>> and GRE  packets just hapily fly back and forth!
>>>>>> Stopped the old service and started shorewall. Another tcpdump showed no
>>>>>> GRE packets being masq'd out. I can rule out anything with the kernel as
>>>>>> that is the same for both firewall generators!
>>>>>>
>>>>>> Maybe it's just me misreading or misunderstanding the docs!
>>>>>> Or maybe I just need my bum kicked!
>>>>>>
>>>>>> I have bziped up the shorewall dump and it is attached as ross.dump.bz2/
>>>>>
>>>>> Hi Ang,
>>>>>
>>>>> Unfortunately, this dump shows no active connections using tcp port 1723
>>>>> or GRE. Can you capture one that demonstrates the issue?
>>>>
>>>> Me's just a bit flustered! Not thinking straight!
>>>>
>>>> This might just be a tad better! ross1.dump.bz2 attached!
>>>
>>> It doesn't look as though you have any of the helpers enabled. Try
>>> setting AUTOHELPERS=Yes in shorewall.conf.
>>
>> The pptp and gre helpers are built into the kernel. The old script 
>> generated rirewall works just fine.
>> In the meantime I'm going to get pptp setup on the server. At leastthe 
>> customer almost completely at 1239 today so I have time to test and not 
>> affect the staff!
> 
> What is the setting of /proc/sys/net/netfilter/nf_conntrack_helper?

You are running a kernel >= 3.5. So with your script running (assuming
that you 'shorewall clear' before invoking your script), it will be set
to 1. While Shorewall is running, it will be set to 0 and the helpers
must be enabled by one of the following methods:

- You can enable all available helpers by setting AUTOHELPERS=Yes in
  shorewall.conf.
- You can enable individual helpers using the HELPERS option in
  shorewall.conf.
- You can add your own rules in /etc/shorewall/conntrack.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to