Re: [Shorewall-users] shorewall not doing SNAT for proto GRE ?

2006-09-27 Thread Sergio A. Kessler
Tom Eastep wrote: > Sergio A. Kessler wrote: >> hi tom, >> >> Tom Eastep wrote: >>> Sergio A. Kessler wrote: >>> I also tried with: # cat /etc/shorewall/masq ### #INTERFACE SUBNET A

Re: [Shorewall-users] shorewall not doing SNAT for proto GRE ? (with correct module names)

2006-09-26 Thread Tom Eastep
Tom Eastep wrote: > > If you load the kernel pptp helper modules (ipt_conntract_pptp and > ipt_nat_pptp), you won't need the masq entry (or that's my understanding > -- I haven't tried it). I got the module names wrong -- should be: ip_conntrack_pptp ip_nat_pptp -Tom -- Tom Eastep\ Nothin

Re: [Shorewall-users] shorewall not doing SNAT for proto GRE ?

2006-09-26 Thread Tom Eastep
Tom Eastep wrote: > It is working exactly as you *should* expect. The problem is that the > server is sending GRE packets before the client. Normally, that is not a > problem because all outbound traffic is SNATed through the same IP > address. In your case, you want it to get a different source I

Re: [Shorewall-users] shorewall not doing SNAT for proto GRE ?

2006-09-26 Thread Tom Eastep
Sergio A. Kessler wrote: > hi tom, > > Tom Eastep wrote: >> Sergio A. Kessler wrote: >> >>> I also tried with: >>> # cat /etc/shorewall/masq >>> ### >>> #INTERFACE SUBNET ADDRESS PROTO PORT(

Re: [Shorewall-users] shorewall not doing SNAT for proto GRE ?

2006-09-26 Thread Sergio A. Kessler
hi tom, Tom Eastep wrote: > Sergio A. Kessler wrote: > >> I also tried with: >> # cat /etc/shorewall/masq >> ### >> #INTERFACE SUBNET ADDRESS PROTO PORT(S) >> IPSEC >> eth0

[Shorewall-users] shorewall not doing SNAT for proto GRE ?

2006-09-26 Thread Sergio A. Kessler
hi all, I have a problem with a VPN server (poptop) behind a shorewall firewall. according with http://www.shorewall.net/PPTP.htm#ServerBehind (and because the fw have multiple external IP address) I have: /etc/shorewall/rules: ### #AC

Re: [Shorewall-users] shorewall not doing SNAT for proto GRE ?

2006-09-26 Thread Tom Eastep
Sergio A. Kessler wrote: > I also tried with: > # cat /etc/shorewall/masq > ### > #INTERFACE SUBNET ADDRESS PROTO PORT(S) > IPSEC > eth0eth1$EXT_SALIDA > eth