Re: shorewall and wireguard - handshake but no ping

Eddie <[email protected]> Thu, 14 Apr 2022 08:53:10 -0700
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
On 4/14/2022 5:34 AM, Erich Titl wrote:
> Hi NIcola
>
> Am 14.04.2022 um 13:01 schrieb Erich Titl:
>> Hi Nicola
>>
>> Am 14.04.2022 um 12:56 schrieb Nicola Ferrari (#554252):
>>> On 14/04/2022 12:50, Erich Titl wrote:
>>>> No problem whatsoever, I guess you did not specify a wireguard zone 
>>>> and the corresponding rule(s).
>>>
>>> Many thanks Erich for your response!
>>>
>>> I can confirm you I defined a "vpn1" zone as ipv4 in shorewall zones 
>>> and the "wg0" interface in interfaces.
>>>
>>> In policy I have
>>> vpn1    all
>>> all    vpn1
>>>
>>> Which should, afaik, allow all traffic from/to wg0
>>>
>>> Am I missing something else maybe?
>
> What about the tunnels file ?
>
> cheers
>
You probably also need a SNAT rule for MASQERADE.

Cheers.


_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users