Re: [Shorewall-users] IPSec Tunneling

2018-01-05 Thread Colony.three via Shorewall-users
> On 01/05/2018 03:02 PM, Colony.three via Shorewall-users wrote: > >> On 01/05/2018 02:25 PM, Colony.three via Shorewall-users wrote: >> >>> I'm trying to change the listening port of Libreswan using these DNAT >>> entries in rules: >>> DNATnet local:192.168.1.16:500 udp

Re: [Shorewall-users] IPSec Tunneling

2018-01-05 Thread Tom Eastep
On 01/05/2018 03:02 PM, Colony.three via Shorewall-users wrote: > On 01/05/2018 02:25 PM, Colony.three via Shorewall-users wrote: >> >> I'm trying to change the listening port of Libreswan using these DNAT >> entries in rules: >> DNAT    net local:192.168.1.16:500 

Re: [Shorewall-users] IPSec Tunneling

2018-01-05 Thread Tom Eastep
On 01/05/2018 02:46 PM, Colony.three via Shorewall-users wrote: > On 12/14/2017 02:55 PM, cac...@quantum-sci.com > wrote: >> >> On 12/14/2017 02:50 PM, Tom Eastep wrote: >> >> On 12/14/2017 02:28 PM, Colony.three via Shorewall-users wrote: >> >>

Re: [Shorewall-users] IPSec Tunneling

2018-01-05 Thread Colony.three via Shorewall-users
On 01/05/2018 02:25 PM, Colony.three via Shorewall-users wrote: >> I'm trying to change the listening port of Libreswan using these DNAT >> entries in rules: >> DNATnet local:192.168.1.16:500 udp - 5500 >> DNATnet local:192.168.1.16 udp

Re: [Shorewall-users] IPSec Tunneling

2018-01-05 Thread Colony.three via Shorewall-users
On 12/14/2017 02:55 PM, cac...@quantum-sci.com wrote: >> On 12/14/2017 02:50 PM, Tom Eastep wrote: >> >>> On 12/14/2017 02:28 PM, Colony.three via Shorewall-users wrote: >>> I have a VM which is the LAN router, and another VM in the LAN which is the ipsec gateway. (strongswan) I'm

Re: [Shorewall-users] IPSec Tunneling

2018-01-05 Thread Tom Eastep
On 01/05/2018 02:25 PM, Colony.three via Shorewall-users wrote: > I'm trying to change the listening port of Libreswan using these DNAT > entries in rules: > DNAT    net local:192.168.1.16:500  udp  -  5500   > DNAT    net local:192.168.1.16  udp 

Re: [Shorewall-users] IPSec Tunneling

2018-01-05 Thread Colony.three via Shorewall-users
> I'm trying to change the listening port of Libreswan using these DNAT entries > in rules: > DNATnet local:192.168.1.16:500 udp - 5500 > DNATnet local:192.168.1.16 udp ipsec-nat-t - > > ... but this results in the below DROPS. Rather

Re: [Shorewall-users] IPSec Tunneling

2018-01-05 Thread Colony.three via Shorewall-users
I'm trying to change the listening port of Libreswan using these DNAT entries in rules: DNATnet local:192.168.1.16:500 udp - 5500 DNATnet local:192.168.1.16 udp ipsec-nat-t - ... but this results in the below DROPS. Rather than

[Shorewall-users] Shorewall 5.1.11 Beta 2

2018-01-05 Thread Tom Eastep
Shorewall 5.1.11 Beta 2 is now available for testing. Problems Corrected since Beta 1: 1) This release contains defect repair from releases through 5.1.10.2. 2) Previously, when DYNAMIC_BLACKLIST=ipsec..., the CLI required the firewall to be started in order to run the 'allow' command.

Re: [Shorewall-users] Softether

2018-01-05 Thread Ivica Glavocic
On 5.1.2018. 17:22, Tom Eastep wrote: On 01/05/2018 02:40 AM, Ivica Glavocic wrote: No, it does not work after shorewall clear. Then Shorewall isn't blocking the traffic. -Tom My conclusion too. Too bad I can't make it work, looks like I'll have to put SoftEther on separate server. Thanks

Re: [Shorewall-users] Softether

2018-01-05 Thread Tom Eastep
On 01/05/2018 02:40 AM, Ivica Glavocic wrote: > No, it does not work after shorewall clear. Then Shorewall isn't blocking the traffic. -Tom -- Tom Eastep\ Q: What do you get when you cross a mobster with Shoreline, \ an international standard? Washington, USA \ A:

Re: [Shorewall-users] Softether

2018-01-05 Thread Ivica Glavocic
On 5.1.2018. 11:00, Matt Darfeuille wrote: On 1/5/2018 10:25 AM, Ivica Glavocic wrote: On 4.1.2018. 23:31, Tom Eastep wrote: On 01/04/2018 01:51 PM, Ivica Glavocic wrote: On 29.12.2017. 18:10, Tom Eastep wrote: On 12/29/2017 12:48 AM, Ivica Glavocic wrote: Any advice how to set up Shorewall

Re: [Shorewall-users] Softether

2018-01-05 Thread Matt Darfeuille
On 1/5/2018 10:25 AM, Ivica Glavocic wrote: > On 4.1.2018. 23:31, Tom Eastep wrote: >> On 01/04/2018 01:51 PM, Ivica Glavocic wrote: >>> On 29.12.2017. 18:10, Tom Eastep wrote: On 12/29/2017 12:48 AM, Ivica Glavocic wrote: > Any advice how to set up Shorewall and SoftEther VPN server on

Re: [Shorewall-users] Softether

2018-01-05 Thread Ivica Glavocic
On 4.1.2018. 23:31, Tom Eastep wrote: On 01/04/2018 01:51 PM, Ivica Glavocic wrote: On 29.12.2017. 18:10, Tom Eastep wrote: On 12/29/2017 12:48 AM, Ivica Glavocic wrote: Any advice how to set up Shorewall and SoftEther VPN server on same multi homed machine? https://www.softether.org/ Road