On 2/1/11 8:48 PM, Alex wrote: > > I have a few questions pertaining to how shorewall manages VPNs, and > also how it manages virtual interfaces. > > For the VPN (using openswan), for some reason the firewall thinks they > are external packets and are not passed through the VPN tunnel. I've > specified the VPN network in the hosts file, and "vpn" is defined as a > zone. Perhaps I'm not somehow binding the vpn interface to the > firewall as a trusted zone? How do I accomplish that?
You follow the instructions at http://www.shorewall.net/IPSEC-2.6.html. If you have connection problems, then please submit a Shorewall dump as described at http://www.shorewall.net/support.htm#Guidelines > > Regarding virtual interfaces, I've used /sbin/ip in the way described > by the FAQ, but how do I convince shorewall it's a trusted internal > interface on the firewall? Do I always need to reference it as > $FW:192.168.1.2 or is there a way to treat it with the same policy as > the internal $FW interface (192.168.1.1)? > All IP addresses defined on the firewall are part of the $FW zone and are governed by that zone's policies. You can create 'vserver' sub-zones of $FW -- see http://ipv6.shorewall.net/Shorewall_and_Aliased_Interfaces.html#id36135728. -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------ Special Offer-- Download ArcSight Logger for FREE (a $49 USD value)! Finally, a world-class log management solution at an even better price-free! Download using promo code Free_Logger_4_Dev2Dev. Offer expires February 28th, so secure your free ArcSight Logger TODAY! http://p.sf.net/sfu/arcsight-sfd2d
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
