Re: Help Needed - Debugging Implicitly Dropped Forwarded Packets
Federico Sevilla III <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.firehol.user |
|---|---|
| Organization | F S 3 Consulting Inc. |
| Message-ID | <[email protected]> |
Hi Costa, Thank you very much for your prompt and authoritative reply. My comments in-line. On Wed, 2009-12-30 at 18:05 +0200, Costa Tsaousis wrote: > This packet is dropped by the iptables connection tracker, not firehol > rules. You are definitely correct that the iptables connection tracker was getting confused by one machine going through the firewall and the other bypassing it. I've solved the problem by implementing source-based routing on the OpenVZ hardware node, forcing packets to go through the firewall as appropriate. All is well now. Thank you very much. Cheers! -- Federico Sevilla III F S 3 Consulting Inc. http://www.fs3.ph ------------------------------------------------------------------------------ This SF.Net email is sponsored by the Verizon Developer Community Take advantage of Verizon's best-in-class app development support A streamlined, 14 day to market process makes app distribution fast and easy Join now and get one step closer to millions of Verizon customers http://p.sf.net/sfu/verizon-dev2dev _______________________________________________ Firehol-support mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/firehol-support
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQBLQBZs5rCBSJO3Rr4RAsQ5AJ4jTukm4GGF8Iadq7MOEJ9nHP9z8QCfV+Vq wm23eJlMmtn6mmzxnSeILXo= =H5zM -----END PGP SIGNATURE-----