LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
LinkBack Search this Thread
Old 09-25-2007, 02:50 AM   #1
javedmk80
LQ Newbie
 
Registered: Sep 2007
Location: Pakistan
Distribution: Red Hat Enterprise Linux 4.0 AS. CentOS 4.5, CentOS 5.0
Posts: 11

Rep: Reputation: 0
Unhappy Shorewall ver 4.0 loading error


I installed Shorewall-common-4.0.3. I plan to load balance two ISPs. I configured shorewall as follows:
/etc/shorewall/interfaces:
#ZONE INTERFACE BROADCAST OPTIONS
net eth1 detect -
net eth2 detect -

vi /etc/shorewall/providers
#ZONE INTERFACE BROADCAST OPTIONS
net eth1 detect -
net eth2 detect -

/etc/shorewall/zones
#ZONE TYPE OPTIONS IN OUT
# OPTIONS OPTIONS
fw firewall
net ipv4

/etc/shorewall/policy
#SOURCE DEST POLICY LOG LIMIT:BURST
# LEVEL
net net DROP

All this information I got from http://www.shorewall.net/MultiISP.html#Example1
I am also running a Squid ver 2.6 as Transparent Proxy. But when I run /etc/init.d/shorewall start OR service shorewall restart I get the following error:
-------------------------------------------------------
Compiling...
Compiling /etc/shorewall/zones...
Compiling /etc/shorewall/interfaces...
Determining Hosts in Zones...
Preprocessing Action Files...
Pre-processing /usr/share/shorewall/action.Drop...
Pre-processing /usr/share/shorewall/action.Reject...
Compiling /etc/shorewall/policy...
Compiling Kernel Route Filtering...
Compiling Martian Logging...
Compiling /etc/shorewall/providers ...
Compiling /etc/shorewall/masq...
Compiling MAC Filtration -- Phase 1...
Compiling /etc/shorewall/rules...
Generating Transitive Closure of Used-action List...
Processing /usr/share/shorewall/action.Reject for chain Reject...
Processing /usr/share/shorewall/action.Drop for chain Drop...
Compiling MAC Filtration -- Phase 2...
Applying Policies...
Generating Rule Matrix...
Use of uninitialized value in string ne at /usr/share/shorewall-perl/Shorewall/Rules.pm line 1424.
Use of uninitialized value in hash element at /usr/share/shorewall-perl/Shorewall/Rules.pm line 1425.
ERROR: No policy defined for zone fw to zone net
-------------------------------------------------------
Plz tell me in detail (I mean with explanation & don't refer me to any website, plz) WHAT mistake I have done, & WHERE in the configs above as I am tired of reading forums & guides... Thanks in advance

Last edited by javedmk80; 09-25-2007 at 02:58 AM.
 
Old 10-04-2007, 03:16 PM   #2
tellef
LQ Newbie
 
Registered: Aug 2005
Location: Norway
Distribution: Slackware & Debian.
Posts: 23

Rep: Reputation: 15
Quote:
Originally Posted by javedmk80 View Post
ERROR: No policy defined for zone fw to zone net
That is an obvious problem. Shorewall will not start unless you have a set of default policies that includes all the zones you have defined. You need to define a policy like

/etc/shorewall/policy

#SOURCE ZONE DESTINATION ZONE POLICY LOG LEVEL LIMIT:BURST
$FW net ACCEPT
net all DROP info
all all REJECT info

or something else that matches your needs. The point is to apply policies that are default for everything, and then define rules on top to tune in.

The lines above are taken from the manual at shorewall.net
I dont mean to bug you, but it appears you need to go there and read more....
 
Old 10-05-2007, 05:36 AM   #3
javedmk80
LQ Newbie
 
Registered: Sep 2007
Location: Pakistan
Distribution: Red Hat Enterprise Linux 4.0 AS. CentOS 4.5, CentOS 5.0
Posts: 11

Original Poster
Rep: Reputation: 0
Thanks buddy...

Actually the problem was with Chains.pm file. I had to replace that; & then all worked fine...
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Upgrading Samba from ver-3.0.4 to current ver-3.0.21b delamatrix Suse/Novell 3 02-20-2006 10:56 AM
Loading modules error after loading compiled kernel td0l2 Linux - Newbie 12 07-28-2004 11:10 AM
Shorewall Startup Error sovietpower Slackware 4 05-25-2004 04:54 PM
Ver 2 Compiler With Ver 3. Kernel wat to do? cam34 Linux - Software 3 08-31-2003 06:15 PM
Ver. 2 @ Ver. 3 Compiler / WinModem Prob. cam34 Linux - Software 1 08-31-2003 03:55 PM


All times are GMT -5. The time now is 09:10 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration