Re: [Shorewall-users] last missing Shorewall6 piece, ping6 from LAN to 'NET ?

2021-05-20 Thread thad17
Hello Alexander, On Thu, May 20, 2021, at 7:33 AM, Alexander Stoll wrote: > When you recieve only a /64 subnet, this gets gets realy complicated and > depends on every involved software which has to support subnets smaller > than /64. > In this situation you may be better off with a NAT solution.

Re: [Shorewall-users] last missing Shorewall6 piece, ping6 from LAN to 'NET ?

2021-05-20 Thread Alexander Stoll
Am 20.05.2021 um 13:04 schrieb tha...@letterboxes.org: So with this I end up with NAT'd IPv6. Which I thought you weren't supposed to do. yes, this is ugly and something to avoid when ever possible... But I guess if I'm going to have private internal IPv6 addresses, either static &/or

Re: [Shorewall-users] last missing Shorewall6 piece, ping6 from LAN to 'NET ?

2021-05-20 Thread thad17
Hello, > SNAT([2600:::::53]) [2600:::::]/64 enp2s0 > > with that, you should now see the 'echo reply'. Wow, that worked! I just assumed that since I wasn't seeing DROP/REJECT of packets, that I didn't have a problem like that. Never thought that the packets

Re: [Shorewall-users] last missing Shorewall6 piece, ping6 from LAN to 'NET ?

2021-05-19 Thread PGNet Dev
thad, look with tcpdump @ icmp6 traffic across your ext router interface while you ping6 from your lan; for your setup tcpdump -n -i enp2s0 icmp6 you'll likely see 'echo request' going out, from your desktop IP address, but no 'echo reply' returning. the "net" needs to know to

Re: [Shorewall-users] last missing Shorewall6 piece, ping6 from LAN to 'NET ?

2021-05-19 Thread thad17
Matt, On Wed, May 19, 2021, at 3:15 PM, Matt Darfeuille wrote: > To ensure that Shorewall is the issue: > > $ shorewall6 clear > > Is everything working if you disable ('cleared') the firewall? If I do that^^ clear, nothing changes. I can ping everywhere, just like before, EXCEPT from

Re: [Shorewall-users] last missing Shorewall6 piece, ping6 from LAN to 'NET ?

2021-05-19 Thread Matt Darfeuille
On 5/19/2021 7:31 PM, tha...@letterboxes.org wrote: > Hello Matt, > > On Wed, May 19, 2021, at 1:17 PM, Matt Darfeuille wrote: >>> sysctl -a | grep ipv6 | grep "\.forwarding" >>> net.ipv6.conf.all.forwarding = 1 >>> net.ipv6.conf.default.forwarding = 1 >>> net.ipv6.conf.enp2s0.forwarding = 1

Re: [Shorewall-users] last missing Shorewall6 piece, ping6 from LAN to 'NET ?

2021-05-19 Thread thad17
Hello Matt, On Wed, May 19, 2021, at 1:17 PM, Matt Darfeuille wrote: > > sysctl -a | grep ipv6 | grep "\.forwarding" > > net.ipv6.conf.all.forwarding = 1 > > net.ipv6.conf.default.forwarding = 1 > > net.ipv6.conf.enp2s0.forwarding = 1 > > net.ipv6.conf.enp3s0.forwarding = 1 > >

Re: [Shorewall-users] last missing Shorewall6 piece, ping6 from LAN to 'NET ?

2021-05-19 Thread Matt Darfeuille
On 5/19/2021 12:42 PM, tha...@letterboxes.org wrote: > Hi, > > On Wed, May 19, 2021, at 3:34 AM, Tuomo Soini wrote: >> I'd guess you forgot to enable ipv6 forwarding. > > I already set forwarding > > sysctl -a | grep ipv6 | grep "\.forwarding" > net.ipv6.conf.all.forwarding = 1 >

Re: [Shorewall-users] last missing Shorewall6 piece, ping6 from LAN to 'NET ?

2021-05-19 Thread thad17
Hi, On Wed, May 19, 2021, at 3:34 AM, Tuomo Soini wrote: > I'd guess you forgot to enable ipv6 forwarding. I already set forwarding sysctl -a | grep ipv6 | grep "\.forwarding" net.ipv6.conf.all.forwarding = 1 net.ipv6.conf.default.forwarding = 1 net.ipv6.conf.enp2s0.forwarding = 1

Re: [Shorewall-users] last missing Shorewall6 piece, ping6 from LAN to 'NET ?

2021-05-19 Thread Tuomo Soini
On Tue, 18 May 2021 17:57:32 -0400 tha...@letterboxes.org wrote: > Feels like I'm finally close to getting this all working at the same > time. I'm still missing the last piece -- ping6 from LAN to 'NET I'd guess you forgot to enable ipv6 forwarding. -- Tuomo Soini Foobar Linux services +358

[Shorewall-users] last missing Shorewall6 piece, ping6 from LAN to 'NET ?

2021-05-18 Thread thad17
Feels like I'm finally close to getting this all working at the same time. I'm still missing the last piece -- ping6 from LAN to 'NET (1) router ip -6 addr show ... EXT 2: enp2s0: mtu 1500 state UP qlen 1000 inet6