[Partial Solution] Re: Can't run shorewall with kernel 2.6.20.2



On Sat, 10 Mar 2007 18:05:00 -0500
"Roberto C. Sanchez" <roberto@xxxxxxxxxxxx> wrote:

On Sun, Mar 11, 2007 at 12:21:09AM +0200, Micha Feigin wrote:

distribution of Debian

Debian unstable

version of shorewall

3.2.9-1

version of iptables

1.3.6.0debian1-5

method by which kernel was built

Vanilla kernel + software suspend + dsdt fixes (debian doesn't have 2.6.20.2
yet)

I would start by checking the recent messages on the shorewall-users
list. I seem to recall Tom Eastep mentioning some issues with 2.6.20 in
relation to another user's mail. If it is not in the archives, then try
following the directions here: http://shorewall.net/support.htm


That helped a bit. It appears that shorewall requires Ipv4 connection tracking
enabled. Now shorewall comes up and seems to work except that dns requests from
the firewall fail when it is enabled. (I can ping out by address but not by
name)

Regards,

-Roberto



--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • Re: Is shorewall abandoned in sid?
    ... I run pretty much pure Sarge with a few choice backports and then ... Is ipset available as a Debian package or in a Debian package. ... it is needed for some of the functionality of Shorewall. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Is shorewall abandoned in sid?
    ... and was planning to make it pure stable when etch gets released. ... Is ipset available as a Debian package or in a Debian package. ... is needed for some of the functionality of Shorewall. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: My Howto QoS/Trafficshaping - Wondershaper+Shorewall
    ... > Guys/Gals, ... > QoS/Trafficshaping using Shorewall and a Hacked ... To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list ...
    (Fedora)
  • Complaint from Xfce[GNOME] and Debian Reference
    ... No problems evident. ... shorewall after reading shorewall-doc. ... install dnsmasq. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)