|
From: Andrzej O. <an...@ma...> - 2009-12-21 01:01:49
|
Hi, I, Andrzej Odyniec wrote: > Shorewall configuration was this same, but probably interpretation has changed. > Maybe now is used source route (or other new) criterium? > > I need read discussion on Shorewall list and look on counters in netfilter rules. So I solved problem. First half was last kernel patch: 31.7. But the second half is changed interpretation of rp_filter interface parameter in kernels starting from 2.6.31. Now interface rp_filter setting has no precedence over /all/rp_filter but is used max of this two values. Shorewall parameter ROUTEFILTER=No is not working with this kernels, but sets /all/rp_filter to 1 up to last Shorewall 4.4.5.2. So there is need to update Shorewall or set .../all/rp_filter manually in /etc/shorewall/start script adding: echo 0 >/proc/sys/net/ipv4/conf/all/rp_filter ofcourse only, if we need not reverse path filtering (as with dual-homed bgp gate). Andrzej Odyniec |