On 04/16/2016 04:05 PM, [email protected] wrote:
> 
> 
> On Sat, Apr 16, 2016, at 03:17 PM, Tom Eastep wrote:
>> Look at the output of 'shorewall trace compile firewall' -- is an ACCEPT
>> rule being gennerated by your entry in the rules file?
> 
> Thanks for the 'trace' cmd.  Obviously a useful tool I should be using.
> 
> First, though, I found a 
> 
>   OPTIMIZE=23
> 
> in the shorewall conf.
> 
> I don't remember setting that, and don't yet know what it does; Suspect one 
> of the other admins did.
> 
> I commented it out, and now the rules ARE generated and in the firewall.
> 
> Obviously a problem, and I'll read up as to what that OPTIMIZE is doing and 
> use 'trace' to compare.
> 
> Poking around a bit,

What is the rule just before your NTP rule?

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to