I didn't think to make the change you had recommended on 01/03 again
with the new software, apologies.

"interfaces":

#ZONE   INTERFACE       BROADCAST       OPTIONS
net     eth0            detect
dhcp,tcpflags,nosmurfs,routefilter=0,logmartians,required
vpn     tun0            detect          optional,routefilter=0

"providers":

#NAME           NUMBER  MARK    DUPLICATE       INTERFACE       GATEWAY         
OPTIONS
loc             1       1       -               eth0            192.168.0.1     
track,fallback=1
iPredator       2       2       -               tun0            -               
track,balance=2

So tracing back through the steps:

1) I am able to apply the firewall configuration before connecting to
OpenVPN, with a new error:

"
Adding Providers...
   WARNING: Interface tun0 is not usable -- Provider iPredator (2) not Started
   WARNING: No Default route added (all 'balance' providers are down)
   NOTICE: Default route restored
"

2) I am then able to connect to OpenVPN normally.
3) I can then re-apply the firewall configuration without error / warning.
4) I attempt to ping to verify my connection and all such packets are dropped
5) I then disconnect from OpenVPN and I get the error "connect:
Network is unreachable" when attempting to ping / reconnect to OpenVPN
6) I then re-apply my firewall configuration
7) Ping's function normally and I can reconnect to OpenVPN (which
functions normally

The dump attached is taken after step 4, with the above new
configuration applied.

On 1/5/13, Tom Eastep <[email protected]> wrote:
> On 01/05/2013 01:43 PM, f q wrote:
>> Apologies, we've done so much tweaking trying to resolve the issue, I
>> haven't posted a current configuration in a bit.  Here's "providers",
>> I can post the other files as well on request:
>>
>> #NAME                NUMBER  MARK    DUPLICATE       INTERFACE       GATEWAY 
>>         OPTIONS
>> loc          1       1       -               eth0            192.168.0.1     
>> track,balance=1
>> iPredator    2       2       -               tun0            -               
>> track,balance=2
>>
>
> But you didn't make the change that I recommended to put 'balance' on
> iPredator and 'fallback' on 'loc'.
>
> -Tom
> --
> Tom Eastep        \ When I die, I want to go like my Grandfather who
> Shoreline,         \ died peacefully in his sleep. Not screaming like
> Washington, USA     \ all of the passengers in his car
> http://shorewall.net \________________________________________________
>
>

------------------------------------------------------------------------------
Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS,
MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current
with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft
MVPs and experts. SALE $99.99 this month only -- learn more at:
http://p.sf.net/sfu/learnmore_122912
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to