On 03/17/2013 07:41 AM, TJ wrote: > This configuration fails to work correctly. Specifically, using > tcpdump on both ends of tun0 (Jeeves and Pella) and watching the > iptrace output I can see that packets are being intercepted by > squid3, proxied out via tun0, replies come back in on tun0 but do not > reach the original client. I can't be sure if they reach squid3 or > not. Trying a manual connection from Jeeves seems to indicate the > response packets aren't making it to the client process, e.g.: > > $ wget -O - http://gb.archive.ubuntu.com/ubuntu/ > > tries to connect to each of the round-robin IPs associated with the > hostname but eventually fails even though the tcpdump and iptrace > logging shows responses returning via tun0 to Jeeves.
Your system log is likely full of 'Martian' messages. Please confirm. > > This affects LAN clients *and* direct connections from Jeeves whether > or not the Squid transparent proxy is active, which leads me to > believe I'm missing something in the Shorewall configuration. > Probably need to set both log_martians and routefilter to 0 for tun0 in /etc/shorewall/interfaces. -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________
signature.asc
Description: OpenPGP digital signature
------------------------------------------------------------------------------ Everyone hates slow websites. So do we. Make your web apps faster with AppDynamics Download AppDynamics Lite for free today: http://p.sf.net/sfu/appdyn_d2d_mar
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
