Hi, I have a problem using "shorewall restart" with shorewall 4.5.0.1 on
kernel 3.2.10, iptables 1.4.12.1
Shorewall starts correctly at boot time, but then a restart triggers error:
Initializing...
Processing /etc/shorewall/init ...
Command: restart
Processing /etc/shorewall/tcclear ...
Setting up Route Filtering...
Setting up Martian Logging...
Setting up Proxy ARP...
Adding Providers...
Setting up Traffic Control...
Preparing iptables-restore input...
Running debug_restore_input...
iptables: Chain already exists.
ERROR: Command "/sbin/iptables :eth0_masq - [0:0]" Failed
Processing /etc/shorewall/stop ...
Processing /etc/shorewall/tcclear ...
Running debug_restore_input...
IPv4 Forwarding Enabled
Processing /etc/shorewall/stopped ...
Terminated
Running shorewall stop & clear, then "shorewall show nat" shows lots of
chains, eg small sample:
Chain POSTROUTING (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source
destination
1 76 eth0_masq all -- * eth0 0.0.0.0/0
0.0.0.0/0
0 0 eth1_masq all -- * eth1 0.0.0.0/0
0.0.0.0/0
0 0 eth2_masq all -- * eth2 0.0.0.0/0
0.0.0.0/0
0 0 eth3_masq all -- * eth3 0.0.0.0/0
0.0.0.0/0
0 0 wlan1_masq all -- * wlan1 0.0.0.0/0
0.0.0.0/0
0 0 wlan2_masq all -- * wlan2 0.0.0.0/0
0.0.0.0/0
0 0 ppp0_masq all -- * ppp0 0.0.0.0/0
0.0.0.0/0
0 0 ppp1_masq all -- * ppp1 0.0.0.0/0
0.0.0.0/0
0 0 ppp2_masq all -- * ppp2 0.0.0.0/0
0.0.0.0/0
0 0 ppp3_masq all -- * ppp3 0.0.0.0/0
0.0.0.0/0
1 76 ppp10_masq all -- * ppp10 0.0.0.0/0
0.0.0.0/0
0 0 ppp11_masq all -- * ppp11 0.0.0.0/0
0.0.0.0/0
0 0 ppp12_masq all -- * ppp12 0.0.0.0/0
0.0.0.0/0
0 0 ppp13_masq all -- * ppp13 0.0.0.0/0
0.0.0.0/0
Chain eth0_masq (1 references)
pkts bytes target prot opt in out source
destination
1 76 MASQUERADE all -- * * 0.0.0.0/0
0.0.0.0/0
Chain eth1_masq (1 references)
pkts bytes target prot opt in out source
destination
0 0 MASQUERADE all -- * * 0.0.0.0/0
0.0.0.0/0
...
If I clear these manually "iptables -t nat -X", then shorewall starts up
without an error
Further, if I add a DNAT rule, eg:
REDIRECT loc 8000 tcp 80 -
Then the error changes to:
iptables: Chain already exists.
ERROR: Command "/sbin/iptables :dnat - [0:0]" Failed
However, it still seems to be a nat table issue and is resolved by
manually clearing the NAT table with iptables (shorewall clear doesn't
do it)
Grateful for any suggestions?
Thanks
Ed W
------------------------------------------------------------------------------
Try before you buy = See our experts in action!
The most comprehensive online learning library for Microsoft developers
is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3,
Metro Style Apps, more. Free future releases when you subscribe now!
http://p.sf.net/sfu/learndevnow-dev2
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users