Dear list,

when starting Shorewall all traffic from local OpenVPN (2.3.11) is blocked/rejected. Without any firewall rules (“shorewall clear”) all traffic works flawlessly - so I assume it’s not a routing or network error (though I let convince myself ;-) )

Short system information:
CentOS 7.2.1511
Shorewall 5.0.4
OpenVPN 2.3.11

Host has a static route to the destination network (10.249.0.0/16) via a router in between. Transit-LAN is 10.249.100.64/26. OpenVPN subnet is 10.20.40.0/21.
The Router has of course a “backroute” (10.20.40.0/21 via 10.249.100.67)

Short network layout:

HQ (10.249.0.0/16) <—> Router (10.249.100.126) <—> Shorewall & OpenVPN Server (10.249.100.67) <— OpenVPN tunnel —> 10.20.41.3

Pinging (and other connection) from 10.20.41.3 to 10.249.0.15 do not work with Shorewall started. When issuing a “shorewall clear” all connections work.

Please find my “shorewall dump” attached.

Thanks a lot!

Kind regards,
philipp




Attachment: shorewall_dump.txt.gz
Description: GNU Zip compressed data

------------------------------------------------------------------------------
What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic
patterns at an interface-level. Reveals which users, apps, and protocols are 
consuming the most bandwidth. Provides multi-vendor support for NetFlow, 
J-Flow, sFlow and other flows. Make informed decisions using capacity planning
reports.http://sdm.link/zohodev2dev
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to