Re: [Efw-user] Routing and ICMP

2013-08-06 Thread Marco Gabriel - inett GmbH
I explained my problem earlier this thread. I added the routes in the endian 
GUI. But Endian does not set routes, it uses iptables. And that does not work 
for ICMP as it seems, at least not on the endian. 

 
If I set the routes manually, it works as expected. 

 
Best regards,

Marco

 
Von: Jonathan Lessa [mailto:jonathanle...@gmail.com] 
Gesendet: Freitag, 2. August 2013 19:59
An: efw-user@lists.sourceforge.net
Betreff: Re: [Efw-user] Routing and ICMP

 
But you need to add the route to have communication with another network.

What is the problem?

 
If your network gateway is the Endian is it then that should be the routes to 
other networks.

 
2013/8/2 Marco Gabriel - inett GmbH mgabr...@inett.de 
mailto:mgabr...@inett.de 

Understood. I already tried to create a specific rule for ICMP traffic within 
the firewall (exactly at policy based routing). It showed me ICMP 8 and ICMP 30 
to allow, but that didn’t work either.

The only thing that worked so far was adding a route.


Marco

Von: Jonathan Lessa [mailto:jonathanle...@gmail.com 
mailto:jonathanle...@gmail.com ]

Gesendet: Freitag, 2. August 2013 17:33

An: efw-user@lists.sourceforge.net mailto:efw-user@lists.sourceforge.net 
Betreff: Re: [Efw-user] Routing and ICMP

But the issue is not the area in itself, but when do you configure a rule to 
redirect the Endian already takes care of creating a rule in the firewall to 
release this communication. What I asked was to test the firewall to create a 
rule allowing ICMP between these networks.

2013/8/2 Marco Gabriel - inett GmbH mgabr...@inett.de 
mailto:mgabr...@inett.de 
There are two LANs, connected through two cisco boxes. LAN1 contains client and 
cisco box 1, LAN2 contains endian, server and cisco box 2. There is no need to 
play with the zones as everything for LAN1 should be routed through the cisco 
box 2. And that works for all services but ICMP.

Best regards,
Marco


Von: Jonathan Lessa [mailto:jonathanle...@gmail.com 
mailto:jonathanle...@gmail.com ]
Gesendet: Freitag, 2. August 2013 17:23
An: efw-user@lists.sourceforge.net mailto:efw-user@lists.sourceforge.net 
Betreff: Re: [Efw-user] Routing and ICMP

I understood that all involved were on the same LAN green, but in this case 
they are not.
Outside the routing would be interesting to create a rule in the firewall 
between zones. Releasing the ping between the 192.168.10.0/24 
http://192.168.10.0/24 network and the Green Zone.



--
Get your SQL database under version control now!
Version control is standard for application code, but databases havent 
caught up. So what steps can you take to put your SQL databases under 
version control? Why should you start doing it? Read more to find out.
http://pubads.g.doubleclick.net/gampad/clk?id=48897031iu=/4140/ostg.clktrk___
Efw-user mailing list
Efw-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/efw-user


[Efw-user] Automatic LOG delete on Endian? Where to get efw-syslog-2.9.8-1.endian9.noarch.rpm

2013-08-06 Thread Andre Mueller

Endian 2.5.1 Community Version:

Hello

Once again after 3 months on our Endian firewall the partition /var/log 
was filled up. According to the following document (How to avoid running 
out of space to store log files), I set the corresponding setting in 
order that logs are deleted when 15% of remaining free space is reached.

http://help.endian.com/entries/21457211-How-to-avoid-running-out-of-disk-space-to-store-log-files
 


Unfortunately that does not work, neither the default behavior of 
reaching 10% of free space on /var/log. I noted only today that in the 
help documentation there is mentioned the 
efw-syslog-2.9.8-1.endian9.noarch.rpm fixing this issue. On our firewall 
version efw-syslog-2.7.9-1.endian9str is installed. Is there any way to 
get this actual rpm for the community version?

I would be grateful for any hint. Thanks in advance, Andre



--
Get your SQL database under version control now!
Version control is standard for application code, but databases havent 
caught up. So what steps can you take to put your SQL databases under 
version control? Why should you start doing it? Read more to find out.
http://pubads.g.doubleclick.net/gampad/clk?id=48897031iu=/4140/ostg.clktrk
___
Efw-user mailing list
Efw-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/efw-user