Re: [Shorewall-users] Difficult NAT problem

2018-05-04 Thread Norman Henderson
Thanks Tom; the default route is 10.1.0.1 on vlan1: Shorewall 5.1.12.3 Routing at voyage3 - Sat May 5 04:40:55 WAT 2018 Routing Rules 0: from all lookup local 32766: from all lookup main 32767: from all lookup default Table default: Table local: local 192.168.1.40 dev wlan1 proto kern

Re: [Shorewall-users] Difficult NAT problem

2018-05-04 Thread Tom Eastep
On 05/04/2018 11:19 AM, Norman Henderson wrote: > Hello again Tom, After a busy week I got back to this and I have some > interesting data. After a bit more than 2 hours of monitoring, in > tcpdump I found the time that the first packets start to be directed > (inappropriately) via wlan1 to the add

Re: [Shorewall-users] Difficult NAT problem

2018-05-04 Thread Norman Henderson
Hello again Tom, After a busy week I got back to this and I have some interesting data. After a bit more than 2 hours of monitoring, in tcpdump I found the time that the first packets start to be directed (inappropriately) via wlan1 to the address that was the original destination, 10.1.0.252. Arou

Re: [Shorewall-users] interface failover

2018-05-04 Thread Tom Eastep
On 05/03/2018 11:55 PM, Jean-Francois Bogaerts wrote: > Hi, > > I'm trying to implement internet interface failover using foolsm. > Everything works fine except when physical link goes down. > > For example starting the following command when connexion is down. > > shorewall disable etx_ > > Gi

Re: [Shorewall-users] SNAT problem 5.1.12.3

2018-05-04 Thread Tom Eastep
On 05/04/2018 05:08 AM, Huy Bui wrote: > Hi > I am trying to set up SNAT so that smtp traffic from my dmz will have a > source of a certain ip address and the rest can use the default on eth0 > However I keep getting the errorĀ  > > Preparing iptables-restore input... > Running /sbin/iptables-resto

[Shorewall-users] SNAT problem 5.1.12.3

2018-05-04 Thread Huy Bui
Hi I am trying to set up SNAT so that smtp traffic from my dmz will have a source of a certain ip address and the rest can use the default on eth0 However I keep getting the error Preparing iptables-restore input... Running /sbin/iptables-restore ... iptables-restore: line 39 failed ERROR: ipt