Tibbs, Richard wrote:
> I see no reject or drop messages in Shorewall.log.

On either firewall/router, right.

>  BTW, thanks for your clarification on transitivity.... I assume that
> applies also to policy entries.

Yes.

> 
> Is it possible that Shorewall or the routing process could be silently
> dropping some packets?
> 

I suspect that this is a routing problem, which will silently send
packets off into the great void. It is probably on the return path since
most people fiddle for hours configuring/reconfiguring the traffic path
in the forward direction totally forgetting that for a connection to
work, routing in the opposite direction must also be correct.

> The various Shorewall files are

So you believe that the right-hand firewall/router and network
configuration is irrelevant and that the problem couldn't possibly be
there, right? I assume that you believe that because you have only
included the left-hand configuration files.

-Tom
-- 
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ [EMAIL PROTECTED]
PGP Public Key   \ https://lists.shorewall.net/teastep.pgp.key


-------------------------------------------------------
This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting
Tool for open source databases. Create drag-&-drop reports. Save time
by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc.
Download a FREE copy at http://www.intelliview.com/go/osdn_nl
------------------------------------------------------------------------
leaf-user mailing list: [email protected]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to