Tom Eastep wrote:
> Vernon A. Fort wrote:
>   
>> shorewall 3.4.8 on gentoo (kernel 2.6.26-r3).  I'm not sure when this 
>> started but when i change rule or add a new rule, then shorewall restart 
>> (or stop then start).  The OLD rules are still present under iptables -L 
>> -nv.  I stop shorewall and the iptables -L -nv shows no rules.  Start 
>> and it still shows the old rule sets.  Also, i started noticing a 
>> shorewall.{hash} directory showing up under the /tmp directory.  I've 
>> never seen this.
>>
>> Where in the heck to i start looking......?
>>     
>
> I suspect that 'shorewall start' is failing and your saved configuration
> is being installed. What do the final messages of '/sbin/shorewall
> restart' look like?
>
> -Tom
>   
> ------------------------------------------------------------------------
It looked (looks) perfectly normal - no errors.  I also reviewed the 
/var/lib/shorewall/.start and .restart and .restore and it appeared the 
previous settting were IN these files.  I went ahead and updated to the 
4.2.5 version and wiped all the previous configuration directory.  
Re-configured and it started working as expected.

But while tweeking the QOS (tcstart) stuff, it happened just after i did 
a shorewall stop.  until i wiped the lib directory, the start would 
appear normal but the tables looked as if i just  did a stop (only the 
routestopped values were present).  Very odd.....

Vernon

------------------------------------------------------------------------------
Create and Deploy Rich Internet Apps outside the browser with Adobe(R)AIR(TM)
software. With Adobe AIR, Ajax developers can use existing skills and code to
build responsive, highly engaging applications that combine the power of local
resources and data with the reach of the web. Download the Adobe AIR SDK and
Ajax docs to start building applications today-http://p.sf.net/sfu/adobe-com
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to