Re: [Partial Solution] Re: Can't run shorewall with kernel 2.6.20.2



On Mon, 12 Mar 2007 18:59:29 -0400
"Roberto C. Sanchez" <roberto@xxxxxxxxxxxx> wrote:

On Mon, Mar 12, 2007 at 09:00:06AM +0200, Micha Feigin wrote:

That helped a bit. It appears that shorewall requires Ipv4 connection
tracking enabled. Now shorewall comes up and seems to work except that dns
requests from the firewall fail when it is enabled. (I can ping out by
address but not by name)


What are the contents of /etc/shorewall/policy?


$FW all ACCEPT -
net $FW DROP info
all all DROP info

I then add specific incoming ports in /etc/shorewall/rules

Regards,

-Roberto


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • Re: Is shorewall abandoned in sid?
    ... I run pretty much pure Sarge with a few choice backports and then ... Is ipset available as a Debian package or in a Debian package. ... it is needed for some of the functionality of Shorewall. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Is shorewall abandoned in sid?
    ... and was planning to make it pure stable when etch gets released. ... Is ipset available as a Debian package or in a Debian package. ... is needed for some of the functionality of Shorewall. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • [Partial Solution] Re: Cant run shorewall with kernel 2.6.20.2
    ... I seem to recall Tom Eastep mentioning some issues with 2.6.20 in ... Now shorewall comes up and seems to work except that dns requests from ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Help - Restrict root privileges - What is indispensable?
    ... i would like to restrict the privileges of root. ... Can access to my frontend netfilter shorewall. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Complaint from Xfce[GNOME] and Debian Reference
    ... No problems evident. ... shorewall after reading shorewall-doc. ... install dnsmasq. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)