Re: [Shorewall-users] shorewall with rocky 9

2024-02-15 Thread rcortes
Hi! With shorewall 5.2.8? Thx. El 2024-02-14 11:28, Nigel Aves escribió: All I'm doing is saying how it works on my server. On Wed, Feb 14, 2024 at 7:05 AM Tuomo Soini wrote: On Wed, 14 Feb 2024 06:35:02 -0700 Nigel Aves wrote: I had a similar issue with Debian 12 ,,, Discovered this

Re: [Shorewall-users] shorewall with rocky 9

2024-02-14 Thread Nigel Aves
All I'm doing is saying how it works on my server. On Wed, Feb 14, 2024 at 7:05 AM Tuomo Soini wrote: > On Wed, 14 Feb 2024 06:35:02 -0700 > Nigel Aves wrote: > > > I had a similar issue with Debian 12 ,,, Discovered this works in the > > snat file: > > > > MASQUERADE enp38s0 enp36s0 > > This i

Re: [Shorewall-users] shorewall with rocky 9

2024-02-14 Thread Tuomo Soini
On Wed, 14 Feb 2024 06:35:02 -0700 Nigel Aves wrote: > I had a similar issue with Debian 12 ,,, Discovered this works in the > snat file: > > MASQUERADE enp38s0 enp36s0 This is not correct syntax. Like man page shorewall-snat says: #ACTIONSOURCE DEST MASQUERADE 192.168.0.0/24

Re: [Shorewall-users] shorewall with rocky 9

2024-02-14 Thread Nigel Aves
I had a similar issue with Debian 12 ,,, Discovered this works in the snat file: MASQUERADE enp38s0 enp36s0 Might be worth a try. Nigel. On Wed, Feb 14, 2024 at 3:22 AM wrote: > Hi! > > is a simple scenario with 2 NIC, WAN and LAN. > > LAN-> WAN with full access > > same config with shorewall

Re: [Shorewall-users] shorewall with rocky 9

2024-02-14 Thread Rodrigo Araujo
Hi. If you are migrating between versions, make a backup of the configuration and do a "shorewall upgrade" before starting shorewall. Ensure firewalld is stopped and disabled (this is important, or else "pure" nftable rules it generates will take precedence). Also make sure that the interfa

Re: [Shorewall-users] shorewall with rocky 9

2024-02-14 Thread rcortes
Hi! is a simple scenario with 2 NIC, WAN and LAN. LAN-> WAN with full access same config with shorewall 5.1 dont work with 5.2 snat file contain: MASQUERADE 192.168.1.0/24 enp32s0f0 shorewall.conf change startup=YES some command to try debug why work with 5.1 but same

Re: [Shorewall-users] shorewall with rocky 9

2024-02-13 Thread Tuomo Soini
On Tue, 13 Feb 2024 21:15:52 + Rodrigo Araujo wrote: > It works fine here with rpms rebuilt from the Fedora src.rpm packages > and iptables-legacy packages from EPEL. > > Ensure you remove (or at least disable and stop) firewalld, and also > make sure the ipset package is installed. Other th

Re: [Shorewall-users] shorewall with rocky 9

2024-02-13 Thread Rodrigo Araujo
It works fine here with rpms rebuilt from the Fedora src.rpm packages and iptables-legacy packages from EPEL. Ensure you remove (or at least disable and stop) firewalld, and also make sure the ipset package is installed. Other than that, I'm not remembering anything. On Tue, 13 Feb 2024, 20:33 Ma

Re: [Shorewall-users] shorewall with rocky 9

2024-02-13 Thread Matt Darfeuille
On 2/13/24 20:16, rcor...@edos.cl wrote: Hi! with rocky try with shorewall 5.2.8 and masq dont work, but with centos7 the same version dont work, only work with 5.1.10. Exist some tips or parameters different? Thx El 2024-02-13 10:34, rcor...@edos.cl escribió: Hi! somebody know why mas

Re: [Shorewall-users] shorewall with rocky 9

2024-02-13 Thread rcortes
Hi! with rocky try with shorewall 5.2.8 and masq dont work, but with centos7 the same version dont work, only work with 5.1.10. Exist some tips or parameters different? Thx El 2024-02-13 10:34, rcor...@edos.cl escribió: Hi! somebody know why masquerade dont work with rocky9? I dont foun

[Shorewall-users] shorewall with rocky 9

2024-02-13 Thread rcortes
Hi! somebody know why masquerade dont work with rocky9? I dont found any about that. Thx___ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/shorewall-users