Re: shorewall and wireguard - handshake but no ping
Eddie <[email protected]> Thu, 14 Apr 2022 08:53:10 -0700
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Message-ID | <[email protected]> |
On 4/14/2022 5:34 AM, Erich Titl wrote: > Hi NIcola > > Am 14.04.2022 um 13:01 schrieb Erich Titl: >> Hi Nicola >> >> Am 14.04.2022 um 12:56 schrieb Nicola Ferrari (#554252): >>> On 14/04/2022 12:50, Erich Titl wrote: >>>> No problem whatsoever, I guess you did not specify a wireguard zone >>>> and the corresponding rule(s). >>> >>> Many thanks Erich for your response! >>> >>> I can confirm you I defined a "vpn1" zone as ipv4 in shorewall zones >>> and the "wg0" interface in interfaces. >>> >>> In policy I have >>> vpn1 all >>> all vpn1 >>> >>> Which should, afaik, allow all traffic from/to wg0 >>> >>> Am I missing something else maybe? > > What about the tunnels file ? > > cheers > You probably also need a SNAT rule for MASQERADE. Cheers. _______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users