Discussion:
[Shorewall-users] PPTP Problem
Hill, John
2016-08-04 16:08:59 UTC
Permalink
I did check the FAQ.
I know the rules :) (I may not have followed them?)

I could see the protocol 47 hit the firewall. It just never got to my internal server
All I had done was upgrade and dist-upgrade from Wheezy to Jessie. It was working on Wheezy?
In the process moving unexpectedly from SysV to Systemd. I was not aware SysV was broke?
Reinstalled Shorewall, samething.

I rewrote the DNAT rule to redirect from only one interface and it works.

OLD: DNAT net local:192.168.xxx.xx x tcp 1723
DNAT net local:192.168.xxx.xxx 47
NEW:DNAT net local:192.168.xxx.xx x tcp 1723 - 12.xxx.xxx.xxx
DNAT net local:192.168.xxx.xxx 47 - - 12.xxx.xxx.xxx

I was planning on moving VPN traffic to this interface exclusively anyway.
I'm going over my configurations to see where I might have it screwed up.

Shorewall has always performed for me. Great product, tons of effort on your part.
Just reading the docs and FAQ's supply lessons in networking.

Thank you Tom.


--john hill
Tom Eastep
2016-08-05 03:33:38 UTC
Permalink
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Post by Hill, John
I rewrote the DNAT rule to redirect from only one interface and it works.
OLD: DNAT net local:192.168.xxx.xx x tcp
1723
DNAT net local:192.168.xxx.xxx 47
NEW:DNAT net local:192.168.xxx.xx x tcp
1723 - 12.xxx.xxx.xxx
DNAT net local:192.168.xxx.xxx 47 -
- 12.xxx.xxx.xxx
I was planning on moving VPN traffic to this interface exclusively anyway.
Glad you got it working -- but to my eye, the OLD and NEW are
identical :-)

- -Tom
- --
Tom Eastep \ When I die, I want to go like my Grandfather who
Shoreline, \ died peacefully in his sleep. Not screaming like
Washington, USA \ all of the passengers in his car
http://shorewall.net \________________________________________________
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
Comment: GPGTools - http://gpgtools.org

iQIcBAEBCAAGBQJXpAkSAAoJEJbms/JCOk0Qc5IP/iAstV+ruy0paLY2P7w9I6yY
0fehT6C8HsbS8xWp5WV3IgPhBZvT7vKFZFFeevEFj3fJfAd6JieX/pQDL4QNit1s
ChRmpkQYXnDgAIGKFbEZ7G+q/S2kPZGgDNDzJ8LOE8Jru1G6Ym9bYV8jdesZabYH
CkXOA+1Ca1F8qiowWFavXlnf+e7sN5MQEQtPTeEpTzhv6br3R9A7KVh+nJvxbUeh
tHuVY3ZOZrO9zKrhtN1/AwsHFj/mOh/+uAh0iWO8XmHk/sMoUvRa20HoQPFAfuj8
pjdSgeyJQE6dMi0Yqf9ONLb73N7x4Q7h31M8DnqwhQDpEBh3o1YoWVAtN0AjTQ82
pZcB7IY+E0gMMMGvM/4vmKnxSfZJSkEclQ1OUn9ZHYN1Efke0xBv7VVYlfwwDr07
p1d1aUNO7gI8nnP44UPN/UZYlvl7YJE1tIXvKwa2YLB4pxs8FWjG/l1FV/O085cP
Gf2DcpXoyi3Bw/BUFSMBtgtps2ruh9oI8Qea9VcePwwJRJE9Cmtg/op9NlCDcs1C
WklD4nR2uyL0vUe/V+Y47C0Ha+7LL1XpqjHWaKutaN0vYUVjiQFaOnHCdrSe1uEC
iNwIhGUWZ27/6NuLnzwkQOfVr2rqEpaKJEbgZvjvjPJsVm0oMGZxUn0TgOcU9h+I
7eZzhVRjDkxdTq5Vy6/c
=3Mcq
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
Tom Eastep
2016-08-05 03:53:11 UTC
Permalink
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Post by Tom Eastep
Post by Hill, John
I was planning on moving VPN traffic to this interface
exclusively anyway.
Glad you got it working -- but to my eye, the OLD and NEW are
identical :-)
Ah -- when seen in my reformatted response, the change is apparent --
you added an entry in the ORIGDEST column in both rules. I hate
mailers that fold text (even though I use one :-) )

- -Tom
- --
Tom Eastep \ When I die, I want to go like my Grandfather who
Shoreline, \ died peacefully in his sleep. Not screaming like
Washington, USA \ all of the passengers in his car
http://shorewall.net \________________________________________________
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
Comment: GPGTools - http://gpgtools.org

iQIcBAEBCAAGBQJXpA2nAAoJEJbms/JCOk0QPlgP/1M2Dl7YjDRn4A5op+O0AMfA
hKX1H+Ps1iiheyDhRySB9Wv/QevnAs3jDtO0Mq7wuLccK16ysFI+e3fOin8fcCe1
Pu7jDu7ZntPLsld40XdMmSoIQiI2hlhdKems0Q8rXS0AUllqnyoKaJJJnXXhYB36
CZgH2EXhEsLhweU/glJASQVG6zs7nVKW9lsa+o3AfruQBmgtaLpd2zfHnwn6wfFX
dbxoGyF7vA32trnJksbPHrEhJV/EyIJUAsxfffyI1EumpFNfwi+dwkD6vdKoiR4E
d+MgzR6jjMhct9fV+cTY82DlXdgfi3XXJWaJLVlwJLDX3+hPmZ+H7gj1PlzUC3jh
X6rCG3MPJkysIKJsctrVBIujdUVOiCcD9Ryj4nw4ZrMs6bejtJWPNMHAgxTQ+N1Q
p1Aw+ojtyOYkjPxybhgwynmKODfOKFF58E3dyjnlJPEYIw0/eisadMgSwfR23O+2
SpBvYY51k0eX9MWDplPKiEHAldVzXGS7EpOQhhg1VC/IFveunn/EZpafzfjGdGuK
gxgRFmjffhxwie8wL5qM6NARgxtKG9xO6WR0SMpITyB6Hf58wsRROX4Ij3X1E5ht
gq1NGtNjWMSOj6npjYfCXEyPl2XQpocRtsI1xPfl5vW3FxfuW/ZRJHr2pNkr0NXe
RLYYfd8f1Ub1Kgbf+hX2
=FQ54
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
Continue reading on narkive:
Loading...