Re: Help Needed - Debugging Implicitly Dropped Forwarded Packets

Federico Sevilla III <[email protected]>
Newsgroups gmane.comp.security.firewalls.firehol.user
Organization F S 3 Consulting Inc.
Message-ID <[email protected]>
Hi Costa,

Thank you very much for your prompt and authoritative reply. My comments
in-line.

On Wed, 2009-12-30 at 18:05 +0200, Costa Tsaousis wrote:
> This packet is dropped by the iptables connection tracker, not firehol 
> rules.

You are definitely correct that the iptables connection tracker was
getting confused by one machine going through the firewall and the other
bypassing it.

I've solved the problem by implementing source-based routing on the
OpenVZ hardware node, forcing packets to go through the firewall as
appropriate.

All is well now.

Thank you very much.

Cheers!

-- 
Federico Sevilla III
F S 3 Consulting Inc.
http://www.fs3.ph

------------------------------------------------------------------------------
This SF.Net email is sponsored by the Verizon Developer Community
Take advantage of Verizon's best-in-class app development support
A streamlined, 14 day to market process makes app distribution fast and easy
Join now and get one step closer to millions of Verizon customers
http://p.sf.net/sfu/verizon-dev2dev

_______________________________________________
Firehol-support mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/firehol-support
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQBLQBZs5rCBSJO3Rr4RAsQ5AJ4jTukm4GGF8Iadq7MOEJ9nHP9z8QCfV+Vq
wm23eJlMmtn6mmzxnSeILXo=
=H5zM
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.