On 03/17/2013 07:41 AM, TJ wrote:

> This configuration fails to work correctly. Specifically, using
> tcpdump on both ends of tun0 (Jeeves and Pella) and watching the
> iptrace output I can see that packets are being intercepted by 
> squid3, proxied out via tun0, replies come back in on tun0 but do not
> reach the original client. I can't be sure if they reach squid3 or
> not. Trying a manual connection from Jeeves seems to indicate the
> response packets aren't making it to the client process, e.g.:
> 
> $ wget -O - http://gb.archive.ubuntu.com/ubuntu/
> 
> tries to connect to each of the round-robin IPs associated with the
> hostname but eventually fails even though the tcpdump and iptrace
> logging shows responses returning via tun0 to Jeeves.

Your system log is likely full of 'Martian' messages. Please confirm.

> 
> This affects LAN clients *and* direct connections from Jeeves whether
> or not the Squid transparent proxy is active, which leads me to
> believe I'm missing something in the Shorewall configuration.
> 

Probably need to set both log_martians and routefilter to 0 for tun0 in
/etc/shorewall/interfaces.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: OpenPGP digital signature

------------------------------------------------------------------------------
Everyone hates slow websites. So do we.
Make your web apps faster with AppDynamics
Download AppDynamics Lite for free today:
http://p.sf.net/sfu/appdyn_d2d_mar
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to