Richard Verdugo wrote:
I sent my shorewall config to [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]> as instructed.

And regarding those NAT entries we have several machines inside our office that need to be accessible via the internet. That is working perfectly.

just fyi, the firewall is a Debian 4.0 system, and the bridge is being created with the bridge-start script that comes with openvpn. The shorewall compiler on this system is perl so I'm using the bridge port set up explained in the docs.

Thank you for your help on this.

The configuration that you sent doesn't match the dump. Please:

a) /sbin/shorewall restart
b) shorewall show chain br0_fwd

The last rule in that chain should be an ACCEPT rule with 'br0' in the 'out' column.

Is that the case?

-Tom
--
Tom Eastep    \ Nothing is foolproof to a sufficiently talented fool
Shoreline,     \ http://shorewall.net
Washington USA  \ [EMAIL PROTECTED]
PGP Public Key   \ https://lists.shorewall.net/teastep.pgp.key

Attachment: signature.asc
Description: OpenPGP digital signature

-------------------------------------------------------------------------
Check out the new SourceForge.net Marketplace.
It's the best place to buy or sell services for
just about anything Open Source.
http://sourceforge.net/services/buy/index.php
_______________________________________________
Shorewall-users mailing list
Shorewall-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to