Paul | 1 Apr 2005 01:02

Re: WebGUI Scripts published

excellent !!!
I'm in the process of rebuilding my firewall now (practising what I preach)

I'll chuck this on, and see how it goes.
Paul.
Andrea Galmacci - awd wrote:

>As promised...
>
>http://www.awd.it/awdwall
>
>One more indication (last minute flash): the .htpasswd provided with the
>tarball has to be canceled - to create a new one please go there
>http://www.flash.net/cgi-bin/pw.pl
>
>
>My .02,
>Andrea
>
>
>----- Original Message ----- 
>From: "Andrea Galmacci - awd" <andrea <at> awd.it>
>To: "Shorewall Users Mailing List" <shorewall-users <at> lists.shorewall.net>
>Sent: Wednesday, March 09, 2005 5:25 PM
>Subject: [Shorewall-users] WebGUI Scripts announcement
>
>
>  
>
>>Dear Shorewall Users, having noticed that the request for a WebGUI is
(Continue reading)

Tom Eastep | 1 Apr 2005 02:05
Favicon

Shorewall 2.0.17

This minor release includes some bugfix back-ports from 2.2.

1) Invoking the 'rejNotSyn' action results in an error at startup.

2) The UDP and TCP port numbers in /usr/share/shorewall/action.AllowPCA
   were reversed.

3)  If a zone is defined in /etc/shorewall/hosts using
   <interface>:!<network> in the HOSTS column then startup errors occur
   on "shorewall [re]start".

http://shorewall.net/pub/shorewall/2.0/shorewall-2.0.17
ftp://shorewall.net/pub/shorewall/2.0/shorewall-2.0.17

-Tom
--

-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ teastep <at> shorewall.net
PGP Public Key   \ https://lists.shorewall.net/teastep.pgp.key
Paul | 1 Apr 2005 02:06

Just getting prepared

Hi guys/gals .. as mentioned earlier I'm rebuilding my fw.

I have shorewall/iptables/kernel blah blah all ready to go.
I've written some udev rules so that I can have
lan0, wave0, wave0:1, golive0, iconz0 as my interface names (might make
for easy maintenance .. named after each ISP)

The ongoing struggle is VPN.
pptp with mppe is being a pig.
ipsec/racoon didn't work last time :(
I read Tom's docs at http://www.shorewall.net/OPENVPN.html and it
doesn't look all bad :)

Is there anything that I should "look out" for?

Ta.
Paul.
Johannes Graumann | 1 Apr 2005 05:33
Picon
Favicon

Samba forwarding?

Hello,

I'm having a problem here with my setup which I could use some hints in
 the right direction with.
I want to do the following :
- Windows boxes (Instrumentation, not my choice ...) are supposed to
  samba into a linux fileserver (131.215.52.67) 
- they don't see the net directly, but are walled up behind a linux
  firewall (172.16.0.1/131.215.35.26)
- both linux machines are running shorewall

windozes   Firewall   Fileserver
   \________^    \_______^

I'm in way over my head and am not looking for solution of a particular 
problem with shorewall but for a sanity check on my general approach to 
this - so one might call this off-topic?
Does anybody have any hints for me?

Thanks for your time, Joh

The firewall was set up with help from samples-2.2.0/two-interfaces.tgz
 and runs 2.2.1 (Debian Testing).
The policy file looks as follows:
fw	net	ACCEPT
net	all	DROP	info
fw	loc	ACCEPT
loc	fw	ACCEPT
all	all	REJECT	info

(Continue reading)

Tom Eastep | 1 Apr 2005 16:33
Favicon

Re: Samba forwarding?

On Thursday 31 March 2005 19:33, Johannes Graumann wrote:
> Hello,
>
> I'm having a problem here with my setup which I could use some hints in
>  the right direction with.
> I want to do the following :
> - Windows boxes (Instrumentation, not my choice ...) are supposed to
>   samba into a linux fileserver (131.215.52.67)
> - they don't see the net directly, but are walled up behind a linux
>   firewall (172.16.0.1/131.215.35.26)
> - both linux machines are running shorewall
>
> windozes   Firewall   Fileserver
>    \________^    \_______^
>
> I'm in way over my head and am not looking for solution of a particular
> problem with shorewall but for a sanity check on my general approach to
> this - so one might call this off-topic?
> Does anybody have any hints for me?
>

Yes -- use a VPN solution. I don't believe that you'll ever get that mess to 
work.

-Tom
--

-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ teastep <at> shorewall.net
PGP Public Key   \ https://lists.shorewall.net/teastep.pgp.key
(Continue reading)

Tom Eastep | 1 Apr 2005 16:38
Favicon

Re: Samba forwarding?

On Thursday 31 March 2005 19:33, Johannes Graumann wrote:
> Hello,
>
> I'm having a problem here with my setup which I could use some hints in
>  the right direction with.
> I want to do the following :
> - Windows boxes (Instrumentation, not my choice ...) are supposed to
>   samba into a linux fileserver (131.215.52.67)
> - they don't see the net directly, but are walled up behind a linux
>   firewall (172.16.0.1/131.215.35.26)
> - both linux machines are running shorewall
>
> windozes   Firewall   Fileserver
>    \________^    \_______^
>
> I'm in way over my head and am not looking for solution of a particular
> problem with shorewall but for a sanity check on my general approach to
> this - so one might call this off-topic?
> Does anybody have any hints for me?
>

Yes -- use a VPN solution rather than trying to mount the shares directly. I 
think you'll have much better success.

If you create a VPN between the Firewall and the Server and run a WINS server 
(Samba can do this) you should be able to get this to work fairly easily.

-Tom
--

-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
(Continue reading)

stewart | 1 Apr 2005 19:25
Picon

Problems using VMWare with a Bridged Firewall

Hi

I am using Shorewall with a bridged Firewall using the "bridging utils" from 
Debian.

eth0 is connected to the router and eth1 is connected to the local lan.

eth0 and eth1 are both assigned zero addresses and br0 is assigned the 
Firewall server address of 192.168.0.1

I should point out that Shorewall is working fine in Bridge mode, but I have 
hit some problems while evaluating VMWare Beta 5 on the same server that is 
acting as an EtherBridge and also running Shorewall.

I am testing Win2k in the Guest environment within VMWare.

I have tried setting up VMWare in two modes :-

a) firstly using NAT between the Virtual server and the Real Host. This works 
although there were a number of broadcasts showing up in the logs

b) secondly ( and currently ) creating a VMWare bridge between the Virtual 
server and br0 on the actual host ( eth0 and eth1 don't have any ip addresses 
assigned to them due to the Ether Bridge ). This also works apart from not 
being able to connect to the Real Host ( bro 192.168.0.1 ) from the Virtual 
server. I can access everything else either on the local net or via the 
Internet. I cannot ping or create a virtual drive from the Virtual server  to 
the Real server 192.168.0.1 However, if I disable Shorewall via "shorewall 
clear" then I can both ping and create a virtual drive from the virtual 
server to the real server.
(Continue reading)

Jeff | 1 Apr 2005 20:10

Re: Problems using VMWare with a Bridged Firewall

See below
----- Original Message ----- 
From: "stewart" <stewart <at> soutram.fsnet.co.uk>
To: <shorewall-users <at> lists.shorewall.net>
Sent: Friday, April 01, 2005 12:25 PM
Subject: [Shorewall-users] Problems using VMWare with a Bridged Firewall

> Hi
>
> I am using Shorewall with a bridged Firewall using the "bridging utils"
from
> Debian.
>
> eth0 is connected to the router and eth1 is connected to the local lan.
>
> eth0 and eth1 are both assigned zero addresses and br0 is assigned the
> Firewall server address of 192.168.0.1
>
> I should point out that Shorewall is working fine in Bridge mode, but I
have
> hit some problems while evaluating VMWare Beta 5 on the same server that
is
> acting as an EtherBridge and also running Shorewall.
>
> I am testing Win2k in the Guest environment within VMWare.
>
> I have tried setting up VMWare in two modes :-
>
> a) firstly using NAT between the Virtual server and the Real Host. This
works
(Continue reading)

Tom Eastep | 1 Apr 2005 20:12
Favicon

Re: Problems using VMWare with a Bridged Firewall

stewart wrote:

> 
> a) firstly using NAT between the Virtual server and the Real Host. This works 
> although there were a number of broadcasts showing up in the logs

Given the above information, I certainly hope you don't expect to
diagnose the cause of "... number of broadcasts showing up in the logs".

> b) secondly ( and currently ) creating a VMWare bridge between the Virtual 
> server and br0 on the actual host 
> 
> It seems that in "VMWare Brigdged mode" Shorewall is preventing the Virtual 
> Server from connecting to the Real Server.

> 
> ip addr show
> 1: lo: <LOOPBACK,UP> mtu 16436 qdisc noqueue
>     link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
>     inet 127.0.0.1/8 scope host lo
>     inet6 ::1/128 scope host
>        valid_lft forever preferred_lft forever
> 2: eth0: <BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast qlen 1000
>     link/ether 00:0d:61:1a:e2:25 brd ff:ff:ff:ff:ff:ff
>     inet6 fe80::20d:61ff:fe1a:e225/64 scope link
>        valid_lft forever preferred_lft forever
> 3: eth1: <BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast qlen 1000
>     link/ether 00:04:5a:8c:67:6a brd ff:ff:ff:ff:ff:ff
>     inet6 fe80::204:5aff:fe8c:676a/64 scope link
>        valid_lft forever preferred_lft forever
(Continue reading)

richard | 1 Apr 2005 21:24
Picon
Favicon

DNAT question

If I want to use DNAT to forward data destined for a port on the firewall to a different port on a 
machine behind the firewall, is this this syntax correct?

DNAT net:3599	loc:192.168.0.10	tcp	22

I can find bits at each end in the docs but not both ends.

TIA
richard

Gmane