Re: shorewall with rocky 9

Tuomo Soini <[email protected]> Wed, 14 Feb 2024 15:46:38 +0200
Newsgroups gmane.comp.security.shorewall
Organization Foobar Oy
Message-ID <[email protected]>
On Wed, 14 Feb 2024 06:35:02 -0700
Nigel Aves <[email protected]> wrote:

> I had a similar issue with Debian 12 ,,, Discovered this works in the
> snat file:
> 
> MASQUERADE enp38s0 enp36s0

This is not correct syntax. Like man page shorewall-snat says:

#ACTION    SOURCE              DEST
MASQUERADE 192.168.0.0/24      eth0

So source must be a network, not an interface.

Also note /etc/shoreall/masq is deprecated.

-- 
Tuomo Soini <[email protected]>
Foobar Linux services
+358 40 5240030
Foobar Oy <https://foobar.fi/>