Please pardon the top post but I am sending this from my IPad which I am not 
very good with yet. This is not a Shorewall restriction but is rather a 
restriction of ipsets 

Tom

Sent from my iPad

On Apr 27, 2011, at 12:54 PM, Harry Lachanas <[email protected]> wrote:

> Hi, 
> 
> On a fresh install 
> 
> Debian system ( lenny ) 
> 
> shorewall 4.4.19.1
> 
> Trying to implement the old transparent proxy rule 
> 
> I've tried 
> 
> DNAT     loc:vmbr0:+[!net_direct]    dmz:10.0.21.12:3128    -    
> +[!no_proxy_hosts]
> 
> and it Gives an error  "Invalid ORIGINAL DEST"
> 
> while on an old system with shorewall 3.4.8 on it it passes OK. 
> 
> In my opinion the ORIG DESTINATION column Craves for ipsets. 
> 
> Regards 
> Harry 
> 
> ------------------------------------------------------------------------------
> WhatsUp Gold - Download Free Network Management Software
> The most intuitive, comprehensive, and cost-effective network 
> management toolset available today.  Delivers lowest initial 
> acquisition cost and overall TCO of any competing solution.
> http://p.sf.net/sfu/whatsupgold-sd
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users

------------------------------------------------------------------------------
WhatsUp Gold - Download Free Network Management Software
The most intuitive, comprehensive, and cost-effective network 
management toolset available today.  Delivers lowest initial 
acquisition cost and overall TCO of any competing solution.
http://p.sf.net/sfu/whatsupgold-sd
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to