Philipp Felix Hoefler
2016-07-20 12:24:34 UTC
Dear list,
when starting Shorewall all traffic from local OpenVPN (2.3.11) is
blocked/rejected. Without any firewall rules (âshorewall clearâ) all
traffic works flawlessly - so I assume itâs not a routing or network
error (though I let convince myself ;-) )
Short system information:
CentOS 7.2.1511
Shorewall 5.0.4
OpenVPN 2.3.11
Host has a static route to the destination network (10.249.0.0/16) via a
router in between. Transit-LAN is 10.249.100.64/26. OpenVPN subnet is
10.20.40.0/21.
The Router has of course a âbackrouteâ (10.20.40.0/21 via 10.249.100.67)
Short network layout:
HQ (10.249.0.0/16) <â> Router (10.249.100.126) <â> Shorewall & OpenVPN
Server (10.249.100.67) <â OpenVPN tunnel â> 10.20.41.3
Pinging (and other connection) from 10.20.41.3 to 10.249.0.15 do not
work with Shorewall started. When issuing a âshorewall clearâ all
connections work.
Please find my âshorewall dumpâ attached.
Thanks a lot!
Kind regards,
philipp
when starting Shorewall all traffic from local OpenVPN (2.3.11) is
blocked/rejected. Without any firewall rules (âshorewall clearâ) all
traffic works flawlessly - so I assume itâs not a routing or network
error (though I let convince myself ;-) )
Short system information:
CentOS 7.2.1511
Shorewall 5.0.4
OpenVPN 2.3.11
Host has a static route to the destination network (10.249.0.0/16) via a
router in between. Transit-LAN is 10.249.100.64/26. OpenVPN subnet is
10.20.40.0/21.
The Router has of course a âbackrouteâ (10.20.40.0/21 via 10.249.100.67)
Short network layout:
HQ (10.249.0.0/16) <â> Router (10.249.100.126) <â> Shorewall & OpenVPN
Server (10.249.100.67) <â OpenVPN tunnel â> 10.20.41.3
Pinging (and other connection) from 10.20.41.3 to 10.249.0.15 do not
work with Shorewall started. When issuing a âshorewall clearâ all
connections work.
Please find my âshorewall dumpâ attached.
Thanks a lot!
Kind regards,
philipp