[Security Firewall] Bug in MNF2 masq template

"Dunlop, Sean" <Sean.Dunlop-s5/[email protected]> Fri, 26 Aug 2005 12:43:06 +0800
Newsgroups gmane.linux.mandrake.security.firewall
Message-ID <[email protected]>
I have worked out my problems with the NAT Masq'ing (thanks for all the
responses)

Mandriva,

There is a bug in the MASQ template.

When I try to write a MASQ entry with multiple 'exclusions' (subnets
excluded from the masq'd origin) the /etc/shorewall/masq file is written
incorrectly and the MNF2 GUI stops responding until "shorewall clear"
command at the console.

Masq rule:

ID: 1
Masq Network: eth0!167.30.10.100,167.20.150.150
Through Int: eth3
Optional Network/Host: 203.20.255.128/32
SNAT: --


Results in this: (/etc/shorewall/masq)

eth3:203.20.255.128/32  eth0!167.30.10.100  Address <-- This word should
be the second address?


* Oh also the GUI command that issues a "shorewall clear" does not work
either.


I am not impressed, tonight I am committed to deploying a buggy box of
junk.

Why was this product not fully tested?

Sean Dunlop

Network & Security Administrator
Department of Treasury & Finance

200 St Georges Tce
Perth Western Australia 6000
Ph - (618) 9262 1494
Mb - (618) [0]414 488 504
Email - sean.dunlop-s5/[email protected]
Web - www.dtf.wa.gov.au
message.footer (text/plain, 232 B)
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________