Re: [Shorewall-users] Shorewall and UDP port 500

2006-10-01 Thread C. Albers
Thanks, Tom, for taking the time to clear this up for me. I really appreciate the help. Chad --- Tom Eastep <[EMAIL PROTECTED]> wrote: > C. Albers wrote: > > Hi Tom, > > > > The problem isn't so much that I have made a > > connection > > from loc->net on UDP port 500 (and 1), but the > > o

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-29 Thread Tom Eastep
Tom Eastep wrote: > C. Albers wrote: >> Hi Tom, >> >> The problem isn't so much that I have made a >> connection >> from loc->net on UDP port 500 (and 1), but the >> other way around, net->loc. If I understanding your >> firewall correctly, the rules in the rules config file >> are exceptions

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-29 Thread Tom Eastep
C. Albers wrote: > Hi Tom, > > The problem isn't so much that I have made a > connection > from loc->net on UDP port 500 (and 1), but the > other way around, net->loc. If I understanding your > firewall correctly, the rules in the rules config file > are exceptions to a net->loc DROP policy.

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-29 Thread C. Albers
Hi Tom, The problem isn't so much that I have made a connection from loc->net on UDP port 500 (and 1), but the other way around, net->loc. If I understanding your firewall correctly, the rules in the rules config file are exceptions to a net->loc DROP policy. For example, as an exception, I

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-27 Thread Tom Eastep
Tom Eastep wrote: > C. Albers wrote: >> I have attached both dump files. I don't find >> diff'ing >> the files very informative. Maybe you can see >> something that I can't. >> >> As far as your gut feeling goes, I have no idea how my >> VPN traffic could not touch my firewall and get out on >>

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-27 Thread Tom Eastep
C. Albers wrote: > I have attached both dump files. I don't find > diff'ing > the files very informative. Maybe you can see > something that I can't. > > As far as your gut feeling goes, I have no idea how my > VPN traffic could not touch my firewall and get out on > the internet. There's only

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-27 Thread C. Albers
I have attached both dump files. I don't find diff'ing the files very informative. Maybe you can see something that I can't. As far as your gut feeling goes, I have no idea how my VPN traffic could not touch my firewall and get out on the internet. There's only one way out of my internal lan:

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-26 Thread Paul Gear
Tom Eastep wrote: > Paul Gear wrote: > >> Try this: >> 1. run 'shorewall clear' (to reset your counters) > > Please make that "shorewall reset" -- "shorewall clear" opens your > firewall to the world. Whoops! :-) Paul signature.asc Description: OpenPGP digital signature ---

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-26 Thread Tom Eastep
Paul Gear wrote: > > Try this: > 1. run 'shorewall clear' (to reset your counters) Please make that "shorewall reset" -- "shorewall clear" opens your firewall to the world. > 2. save your 'shorewall dump' output in a file > 3. make a VPN connection through your firewall > 4. save your 'shorewal

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-26 Thread Paul Gear
C. Albers wrote: > Hi Paul, > > Sorry about that. This dump has the udp log messages > in it that relate to the ipsec connections over port > 500 and port 1 - which theorectically, should be > closed, until I open them in the rules config file. > > The log messages occur after the "Chain t

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-26 Thread C. Albers
Hi Paul, Sorry about that. This dump has the udp log messages in it that relate to the ipsec connections over port 500 and port 1 - which theorectically, should be closed, until I open them in the rules config file. The log messages occur after the "Chain tcpre" section. Thanks for your h

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-24 Thread Paul Gear
C. Albers wrote: > Okay. > > Attached is the gzip shorewall dump file. Chad, Could you please make some VPN attempts and take a dump without restarting Shorewall in between? I can't see any evidence of the problem you mentioned in your original post. Regards, Paul signature.asc Description:

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-24 Thread C. Albers
Okay. Attached is the gzip shorewall dump file. Thanks, Chad --- Tom Eastep <[EMAIL PROTECTED]> wrote: > C. Albers wrote: > > I'll send the dump > > file as requested, since I don't exactly fall > inside the #3 flowchart position on the support > guide. > > I guess that I need to change the

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-24 Thread Tom Eastep
C. Albers wrote: > I'll send the dump > file as requested, since I don't exactly fall inside the #3 flowchart > position on the support guide. I guess that I need to change the flowchart to say that "connection problems" include the case where a connection is accepted when the user doesn't think

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-24 Thread C. Albers
age From: Tom Eastep <[EMAIL PROTECTED]> To: Shorewall Users Sent: Sunday, September 24, 2006 5:17:53 PM Subject: Re: [Shorewall-users] Shorewall and UDP port 500 C. Albers wrote: Please configure your mailer to break lines at some reasonable width. Your whole post is one long line!

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-24 Thread Jan Mulders
Post your configuration files (perhaps with IP addresses removed/obfuscated and we'll see where the hole lies!Feel free to contact me off-list.Regards,Jan Mulders On 24/09/06, Tom Eastep <[EMAIL PROTECTED]> wrote: C. Albers wrote:Please configure your mailer to break lines at some reasonable width.

Re: [Shorewall-users] Shorewall and UDP port 500

2006-09-24 Thread Tom Eastep
C. Albers wrote: Please configure your mailer to break lines at some reasonable width. Your whole post is one long line! > I installed shorewall 3.0.7-1 on my Debian box and pretty much ran it out of > the box > Is that the default behavior of shorewall? (I would have assumed that > I need to

[Shorewall-users] Shorewall and UDP port 500

2006-09-24 Thread C. Albers
Hi, I installed shorewall 3.0.7-1 on my Debian box and pretty much ran it out of the box after adding a few macros. I'm running it on a gateway between the net and my local lan. The other day, without thinking, I logged into my work network using a VPN client and it worked. However, I nev