On 03/12/15 18:19, Tom Eastep wrote: [SNIP]
> Please remove /var/lib/shorewall/eth3.status again then execute the > following: > > sh -x /var/lib/shorewall/firewall enable eth3 > trace 2>&1 > > and send me the 'trace' file. > > Thanks, > -Tom Hi Tom, Here you go: ---- cut here ---- + LEFTSHIFT=<< + g_debug_iptables= + [ 2 -gt 1 ] + [ xenable = xtrace ] + [ xenable = xdebug ] + [ -z ] + [ -n ] + g_purge= + g_noroutes= + g_timestamp= + g_recovering= + initialize + umask 077 + g_family=4 + g_confdir=/etc/shorewall + g_product=Shorewall + g_program=shorewall + g_basedir=/usr/share/shorewall + CONFIG_PATH=/etc/shorewall:/usr/share/shorewall + [ -f /etc/shorewall/vardir ] + [ -n /var/lib/shorewall ] + [ -n /var/lib ] + TEMPFILE= + DISABLE_IPV6=Yes + MODULESDIR= + MODULE_SUFFIX=ko + LOAD_HELPERS_ONLY=Yes + SUBSYSLOCK= + LOG_VERBOSITY=2 + [ -n restart ] + [ -n 0 ] + [ -n restore ] + SHOREWALL_VERSION=4.5.21.6 + PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin:/usr/local/sbin + TERMINATOR=fatal_error + DONT_LOAD= + STARTUP_LOG=/var/log/shorewall-init.log + [ -z ] + mywhich iptables + local dir + split /sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin:/usr/local/sbin + local ifs + ifs= + IFS=: + echo /sbin /bin /usr/sbin /usr/bin /usr/local/bin /usr/local/sbin + IFS= + [ -x /sbin/iptables ] + echo /sbin/iptables + return 0 + IPTABLES=/sbin/iptables + [ -n /sbin/iptables -a -x /sbin/iptables ] + IP6TABLES=/sbin/ip6tables + IPTABLES_RESTORE=/sbin/iptables-restore + [ -x /sbin/iptables-restore ] + g_tool=/sbin/iptables + IP=ip + TC=tc + IPSET=ipset + DMZ_IF=eth1 + ECL_IF=eth2 + ETH3_IP=82.9.127.74 + LOC_IF=eth0 + VIR_IF=eth3 + g_stopping= + [ -d /var/lib/shorewall ] + [ -n /var/log/shorewall-init.log ] + touch /var/log/shorewall-init.log + chmod 0600 /var/log/shorewall-init.log + [ 0 -eq 1 ] + finished=0 + [ 0 -eq 0 -a 2 -gt 0 ] + option=enable + finished=1 + [ 1 -eq 0 -a 2 -gt 0 ] + COMMAND=enable + [ 2 -eq 1 ] + shift + [ 1 -ne 1 ] + product_is_started + qt1 /sbin/iptables -L shorewall -n + local status + [ 1 ] + /sbin/iptables -L shorewall -n + status=0 + [ 0 -ne 4 ] + return 0 + detect_configuration + find_first_interface_address_if_any eth3 + [ 4 -eq 4 ] + ip -f inet addr show eth3 + grep inet .* global + head -n1 + addr= inet 82.9.127.74/22 brd 255.255.255.255 scope global eth3 + [ -n inet 82.9.127.74/22 brd 255.255.255.255 scope global eth3 ] + echo inet 82.9.127.74/22 brd 255.255.255.255 scope global eth3 + sed s/\s*inet //;s/\/.*//;s/ peer.*// + SW_ETH3_ADDRESS=82.9.127.74 + [ -n ] + detect_dynamic_gateway eth3 + local interface + interface=eth3 + local GATEWAYS + GATEWAYS= + local gateway + run_findgw_exit eth3 + true + gateway= + [ -z ] + ip addr list eth3 + find_peer 5: eth3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000 link/ether 00:30:18:a1:22:bd brd ff:ff:ff:ff:ff:ff inet 82.9.127.74/22 brd 255.255.255.255 scope global eth3 valid_lft forever preferred_lft forever + [ 28 -gt 1 ] + [ x5: = xpeer ] + shift + [ 27 -gt 1 ] + [ xeth3: = xpeer ] + shift + [ 26 -gt 1 ] + [ x<BROADCAST,MULTICAST,UP,LOWER_UP> = xpeer ] + shift + [ 25 -gt 1 ] + [ xmtu = xpeer ] + shift + [ 24 -gt 1 ] + [ x1500 = xpeer ] + shift + [ 23 -gt 1 ] + [ xqdisc = xpeer ] + shift + [ 22 -gt 1 ] + [ xpfifo_fast = xpeer ] + shift + [ 21 -gt 1 ] + [ xstate = xpeer ] + shift + [ 20 -gt 1 ] + [ xUP = xpeer ] + shift + [ 19 -gt 1 ] + [ xgroup = xpeer ] + shift + [ 18 -gt 1 ] + [ xdefault = xpeer ] + shift + [ 17 -gt 1 ] + [ xqlen = xpeer ] + shift + [ 16 -gt 1 ] + [ x1000 = xpeer ] + shift + [ 15 -gt 1 ] + [ xlink/ether = xpeer ] + shift + [ 14 -gt 1 ] + [ x00:30:18:a1:22:bd = xpeer ] + shift + [ 13 -gt 1 ] + [ xbrd = xpeer ] + shift + [ 12 -gt 1 ] + [ xff:ff:ff:ff:ff:ff = xpeer ] + shift + [ 11 -gt 1 ] + [ xinet = xpeer ] + shift + [ 10 -gt 1 ] + [ x82.9.127.74/22 = xpeer ] + shift + [ 9 -gt 1 ] + [ xbrd = xpeer ] + shift + [ 8 -gt 1 ] + [ x255.255.255.255 = xpeer ] + shift + [ 7 -gt 1 ] + [ xscope = xpeer ] + shift + [ 6 -gt 1 ] + [ xglobal = xpeer ] + shift + [ 5 -gt 1 ] + [ xeth3 = xpeer ] + shift + [ 4 -gt 1 ] + [ xvalid_lft = xpeer ] + shift + [ 3 -gt 1 ] + [ xforever = xpeer ] + shift + [ 2 -gt 1 ] + [ xpreferred_lft = xpeer ] + shift + [ 1 -gt 1 ] + gateway= + [ -z -a -f /var/lib/dhcpcd/dhcpcd-eth3.info ] + [ -z -a -f /var/lib/dhcp/dhclient-eth3.lease ] + [ -n ] + SW_ETH3_GATEWAY= + SW_ETH2_IS_USABLE= + SW_ETH3_IS_USABLE= + interface_is_usable eth2 + local status + status=0 + [ eth2 != lo ] + interface_is_up eth2 + ip -4 link list dev eth2 + grep -e [<,]UP[,>] + [ -n 4: eth2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP mode DEFAULT group default qlen 1000 ] + find_first_interface_address_if_any eth2 + [ 4 -eq 4 ] + ip -f inet addr show eth2 + head -n1 + grep inet .* global + addr= inet 91.85.120.2/28 brd 91.85.120.15 scope global eth2 + [ -n inet 91.85.120.2/28 brd 91.85.120.15 scope global eth2 ] + echo inet 91.85.120.2/28 brd 91.85.120.15 scope global eth2 + sed s/\s*inet //;s/\/.*//;s/ peer.*// + [ 91.85.120.2 != 0.0.0.0 ] + [ enable = enable ] + status=0 + return 0 + SW_ETH2_IS_USABLE=Yes + interface_is_usable eth3 + local status + status=0 + [ eth3 != lo ] + interface_is_up eth3 + ip -4 link list dev eth3 + grep -e [<,]UP[,>] + [ -n 5: eth3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP mode DEFAULT group default qlen 1000 ] + find_first_interface_address_if_any eth3 + [ 4 -eq 4 ] + ip -f inet addr show eth3 + grep inet .* global + head -n1 + addr= inet 82.9.127.74/22 brd 255.255.255.255 scope global eth3 + [ -n inet 82.9.127.74/22 brd 255.255.255.255 scope global eth3 ] + echo inet 82.9.127.74/22 brd 255.255.255.255 scope global eth3 + sed s/\s*inet //;s/\/.*//;s/ peer.*// + [ 82.9.127.74 != 0.0.0.0 ] + [ enable = enable ] + status=0 + return 0 + [ -n ] + enable_provider eth3 + g_interface=eth3 + ip -4 route ls table 2 + [ -z ] + start_provider_VIRG + [ -n ] + echo 1 + error_message WARNING: Interface eth3 is not usable -- Provider VIRG (2) not Started + echo WARNING: Interface eth3 is not usable -- Provider VIRG (2) not Started WARNING: Interface eth3 is not usable -- Provider VIRG (2) not Started + status=0 + exit 0 ---- cut here ---- Cheers, Laurie. -- --------------------------------------------------------------------- www.convergent-ict.com You manage your business. We manage your IT. --------------------------------------------------------------------- ------------------------------------------------------------------------------ Go from Idea to Many App Stores Faster with Intel(R) XDK Give your users amazing mobile app experiences with Intel(R) XDK. Use one codebase in this all-in-one HTML5 development environment. Design, debug & build mobile apps & 2D/3D high-impact games for multiple OSs. http://pubads.g.doubleclick.net/gampad/clk?id=254741911&iu=/4140 _______________________________________________ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/shorewall-users