On 2/1/11 8:48 PM, Alex wrote:

> 
> I have a few questions pertaining to how shorewall manages VPNs, and
> also how it manages virtual interfaces.
> 
> For the VPN (using openswan), for some reason the firewall thinks they
> are external packets and are not passed through the VPN tunnel. I've
> specified the VPN network in the hosts file, and "vpn" is defined as a
> zone. Perhaps I'm not somehow binding the vpn interface to the
> firewall as a trusted zone? How do I accomplish that?

You follow the instructions at http://www.shorewall.net/IPSEC-2.6.html.
If you have connection problems, then please submit a Shorewall dump as
described at http://www.shorewall.net/support.htm#Guidelines
> 
> Regarding virtual interfaces, I've used /sbin/ip in the way described
> by the FAQ, but how do I convince shorewall it's a trusted internal
> interface on the firewall? Do I always need to reference it as
> $FW:192.168.1.2 or is there a way to treat it with the same policy as
> the internal $FW interface (192.168.1.1)?
> 

All IP addresses defined on the firewall are part of the $FW zone and
are governed by that zone's policies. You can create 'vserver' sub-zones
of $FW -- see
http://ipv6.shorewall.net/Shorewall_and_Aliased_Interfaces.html#id36135728.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Special Offer-- Download ArcSight Logger for FREE (a $49 USD value)!
Finally, a world-class log management solution at an even better price-free!
Download using promo code Free_Logger_4_Dev2Dev. Offer expires 
February 28th, so secure your free ArcSight Logger TODAY! 
http://p.sf.net/sfu/arcsight-sfd2d
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to