Discussion:
[Shorewall-users] Routing through a firewall/router
Graumann, Johannes
2017-01-15 14:43:56 UTC
Permalink
...
You have enabled ping to/from the 'fw' zone and from the 'usr' zone to
the other zones only. If ping is failing from the 'usr' zone to one of
the other local zones, then please submit another dump collected as
- - 'shorewall clear'
- - perform the failing ping
- - take the dump
- - when you submit the dump, tell us the source IP and destination IP of
the failing test.
As I indeed am trying to ping from a usr IP (10.10.1.5) to an IP in strg
(10.10.4.3) and it fails, I did as Tom proposed and attach the dump.

Any help is highly appreciated.

Note that the dump opperation throuw an error:

shorewall dump > ping_dump.txt
/sbin/shorewall: 859: [: ping_dump.txt: unexpected operator

Joh
Tom Eastep
2017-01-15 16:58:53 UTC
Permalink
Post by Graumann, Johannes
...
You have enabled ping to/from the 'fw' zone and from the 'usr'
zone to the other zones only. If ping is failing from the 'usr'
zone to one of the other local zones, then please submit another
- - 'shorewall clear' - - perform the failing ping - - take the
dump - - when you submit the dump, tell us the source IP and
destination IP of the failing test.
As I indeed am trying to ping from a usr IP (10.10.1.5) to an IP in
strg (10.10.4.3) and it fails, I did as Tom proposed and attach the
dump.
Any help is highly appreciated.
ping_dump.txt: unexpected operator
Yes -- that is an old bug that is now fixed.

Unfortunately, I gave you incorrect instructions; I mean to have you
'shorewall reset' rather than 'shorewall clear.

That having been said, if it didn't work with 'shorewall clear' then
there is something wrong with your routing. Can all of the subnets
access the internet with shorewall started?

- -Tom
- --
Tom Eastep \ When I die, I want to go like my Grandfather who
Shoreline, \ died peacefully in his sleep. Not screaming like
Washington, USA \ all of the passengers in his car
http://shorewall.net \________________________________________________
Continue reading on narkive:
Loading...