Dear list,when starting Shorewall all traffic from local OpenVPN (2.3.11) is blocked/rejected. Without any firewall rules (“shorewall clear”) all traffic works flawlessly - so I assume it’s not a routing or network error (though I let convince myself ;-) )
Short system information: CentOS 7.2.1511 Shorewall 5.0.4 OpenVPN 2.3.11Host has a static route to the destination network (10.249.0.0/16) via a router in between. Transit-LAN is 10.249.100.64/26. OpenVPN subnet is 10.20.40.0/21.
The Router has of course a “backroute” (10.20.40.0/21 via 10.249.100.67) Short network layout:HQ (10.249.0.0/16) <—> Router (10.249.100.126) <—> Shorewall & OpenVPN Server (10.249.100.67) <— OpenVPN tunnel —> 10.20.41.3
Pinging (and other connection) from 10.20.41.3 to 10.249.0.15 do not work with Shorewall started. When issuing a “shorewall clear” all connections work.
Please find my “shorewall dump” attached. Thanks a lot! Kind regards, philipp
shorewall_dump.txt.gz
Description: GNU Zip compressed data
------------------------------------------------------------------------------ What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic patterns at an interface-level. Reveals which users, apps, and protocols are consuming the most bandwidth. Provides multi-vendor support for NetFlow, J-Flow, sFlow and other flows. Make informed decisions using capacity planning reports.http://sdm.link/zohodev2dev
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
