[Shorewall-users] Intra zone traffic rejected by FORWARD chain

2020-03-25 Thread Kevin Parent
I operate a 5 interface router.  One interface if for all radio (wireless) traffic.  There is only one zone defined for this interface.  It is called "radio" It has multiple subnets both private and public.  Private space is for management -- AP's, routers, wireless client bridges, point to

Re: [Shorewall-users] Intra zone traffic rejected by FORWARD chain

2020-03-25 Thread Justin Pryzby
On Wed, Mar 25, 2020 at 05:14:32PM -0500, Kevin Parent wrote: > I've read the documentation.  It states that intra zone traffic is enabled > by default.  Unfortunately, not in my case. Where does it say that ? I think you need interfaces option "routeback". -- Justin

Re: [Shorewall-users] Intra zone traffic rejected by FORWARD chain

2020-03-25 Thread Kevin Parent
On 3/25/20 7:07 PM, Kevin Parent wrote: On 3/25/20 5:36 PM, Justin Pryzby wrote: On Wed, Mar 25, 2020 at 05:14:32PM -0500, Kevin Parent wrote: I've read the documentation.  It states that intra zone traffic is enabled by default.  Unfortunately, not in my case. Where does it say that ? I

Re: [Shorewall-users] Intra zone traffic rejected by FORWARD chain

2020-03-25 Thread Kevin Parent
On 3/25/20 5:36 PM, Justin Pryzby wrote: On Wed, Mar 25, 2020 at 05:14:32PM -0500, Kevin Parent wrote: I've read the documentation.  It states that intra zone traffic is enabled by default.  Unfortunately, not in my case. Where does it say that ? I think you need interfaces option

Re: [Shorewall-users] Intra zone traffic rejected by FORWARD chain

2020-03-25 Thread Justin Pryzby
On Wed, Mar 25, 2020 at 07:13:50PM -0500, Kevin Parent wrote: > > > I think you need interfaces option "routeback". > > > > In the man file for shorewall zones it states: > >    For $FW and for all of the zones defined in /etc/shorewall/zones, > >    the POLICY for connections from