[Shorewall-users] local network blocking

Tom Eastep teastep at shorewall.net
Thu Oct 16 15:35:05 PDT 2003


On Thu, 2003-10-16 at 13:49, Norbert Crettol wrote:

>  
> Ok, I've tested to "shorewall clear" and it still didn't work. So,
> I've a network config problem. My forwarding is not setup properly.
> I've lost a lot of time tweaking shorewall... I know now where to 
> search. Than you.

These are pretty obvious but maybe one will help:

1) All hosts in the 'local' zone should have their default gateway set
to 192.33.221.2.

2) All hosts in the 153.109.180.0/24 subnet (including 153.109.180.1)
need to have a route to 192.33.221.0/24 via 153.109.180.2.
Alternatively, 154.109.180.1 has such a route and return ICMP redirects
to hosts trying to reach 192.33.221.0/24. There ICMP packets redirect
the client to 154.109.180.2.

3) On your Shorewall box, verify that /proc/sys/net/ipv4/ip_forward
contains 1. Usually, "shorewall clear" will set it that way and
IP_FORWARDING=On sets it that way when Shorewall is started.

-Tom
-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ teastep at shorewall.net




More information about the Shorewall-users mailing list