I see no reject or drop messages in Shorewall.log.
 BTW, thanks for your clarification on transitivity.... I assume that
applies also to policy entries.

Is it possible that Shorewall or the routing process could be silently
dropping some packets?


Rick.

The various Shorewall files are
/etc/Shorewall/interfaces is:
net     eth0    detect  norfc1918
loc     eth1    detect  dhcp
vpn1    ipsec0
vpn3    tun1
vpn4    tun0
 Shorewall policy file:
loc             vpn1            ACCEPT
loc             vpn3            ACCEPT
fw              vpn3            ACCEPT
net             vpn3            ACCEPT
loc             vpn4            ACCEPT
fw              vpn4            ACCEPT
net             vpn4            ACCEPT
vpn3                vpn4                ACCEPT
vpn4                vpn3                ACCEPT
vpn1            loc             ACCEPT
vpn3            loc             ACCEPT
vpn3            fw              ACCEPT
vpn3            net             ACCEPT
vpn4            loc             ACCEPT
vpn4            fw              ACCEPT
vpn4            net             ACCEPT
fw              loc             ACCEPT
net             all             DROP            ULOG
all             all             REJECT          ULOG
#LAST LINE -- ADD YOUR ENTRIES ABOVE THIS LINE -- DO NOT REMOVE

 and zones file is:

#ZONE   DISPLAY         COMMENTS
net     Net             Internet
loc     Local           Local Networks
vpn1    VPN-RW-IPSEC    Road Warrior
vpn3    WLAN-OPENVPN    Openvpn to wireless internal
vpn4    WiredOPENVPN    Openvpn to office firewall
#LAST LINE -- ADD YOUR ENTRIES ABOVE THIS LINE -- DO NOT REMOVE



-----Original Message-----
From: Tom Eastep [mailto:[EMAIL PROTECTED] 
Sent: Sunday, January 23, 2005 11:45 AM
To: Tibbs, Richard
Cc: [email protected]
Subject: Re: [leaf-user] please help: two openvpn tunnels.

Tom Eastep wrote:
> Tibbs, Richard wrote:
> 
>>Dear list, sorry for long post.
>>Bottom line is I can ping everything except machines on 192.168.10.0
>>from winxp.
>>
>>I have the config below, with this arrangement:
>>winxp -- wlan --    Linuxfw1 -- Internet -- LinuxFw2 --
192.168.10.0/24 
>>openvpn             openvpn                openvpn
>>2.0.15beta           1.6.0                   1.6.0
>>10.1.1.2      10.1.1.1  10.1.10.1         10.1.10.2
>><     tunnel 1      >    <     tunnel 2         >  
>>
>>The linuxfw's are Bering 1.2.
>>
> 
> 
> And what do their Shorewall configs look like?
> 

And of course: Are you seeing any Shorewall messages on either fw/router
during the ping failures?

-Tom
-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ [EMAIL PROTECTED]
PGP Public Key   \ https://lists.shorewall.net/teastep.pgp.key



-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl
------------------------------------------------------------------------
leaf-user mailing list: [email protected]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to