Re: [Shorewall-users] some ICMPv6 messages don't make it through SNAT

2024-03-14 Thread Uwe B
On 3/13/24 18:31, Tuomo Soini wrote: ... Note rplog here. That means rpfilter is preventing this packet. That means you have a problem with routing. I can't follow. How can routing be dependent on the type of ICMP6 packet? The connection works fine for "normal packets" I did a "shorewall6

Re: [Shorewall-users] some ICMPv6 messages don't make it through SNAT

2024-03-13 Thread Tuomo Soini
On Wed, 13 Mar 2024 18:00:20 +0100 Uwe B wrote: > This tells me that everything works (unfiltered) as it should up to > Interface AMS2. > > In the meantime I noticed that there are entries in a log > (pve-firewall.log) which I did not configure (the system is a proxmox > setup): > 0 6 - 13/Ma

Re: [Shorewall-users] some ICMPv6 messages don't make it through SNAT

2024-03-13 Thread Uwe B
On 3/13/24 16:36, Tuomo Soini wrote: On Wed, 13 Mar 2024 15:37:31 +0100 Uwe Behle wrote: Good afternoon, first, the mandatory information; for brevity since the problem lies in ipV6, for V6 only: shorewall6 version 5.2.8 Shorewall especially has rules to allow required ICMPv6 messages so s