Re: ejabberd DNAT problem

Phil Stracchino <[email protected]> Wed, 19 Apr 2023 17:52:43 -0400
Newsgroups gmane.comp.security.shorewall
Organization Babylon Communications
Message-ID <[email protected]>
On 4/18/23 23:19, Justin Pryzby wrote:
> On Tue, Apr 18, 2023 at 12:02:56AM -0400, Phil Stracchino wrote:
>>>> Can anyone suggest to me why my firewall is apparently ignoring my
>>>> instructions to accept and DNAT XMPP traffic?
>>>
>>> Are the rules being hit ?
>>>
>>> Either add ":info:xmpp"
>>
>> Add that to what?
> 
> to the end of your rules' "actions"
> https://shorewall.org/manpages/shorewall-rules.html


Whatever was going on, either resolved itself or I was able to resolve 
it.  I'm not entirely happy about this, because it means I can no longer 
identify the problem, since it's no longer happening, which means I 
can't determine what went wrong, which means I can't take precautions 
against it happening again.


I *did* comment out the Jabber...(ACCEPT) macros and rely just on the 
DNATs, per your observation.  That so far seems to be working fine.



-- 
   Phil Stracchino
   Babylon Communications
   [email protected]
   [email protected]
   Landline: +1.603.293.8485
   Mobile:   +1.603.998.6958