I’m having a slight issue with the firewall, dropping connections with the sfilter.
My scenario, I have multiple LAN clients connecting through the NS box. I have 2 NIC’s in the NS box. 1 NIC is on the RED , and the other on the GREEN zones.
For the most part, everything is working, LAN clients can pickup their mail and browse the internet.
In the morning when clients power up their PC, they have no internet connection. I see entries in the firewall.log , with the sfilter as below. I’ve removed the MAC’s
Now, if I ping the client IP from the NS box , its all starts working.
Restarting the firewall has no affect. Once the firewall restarts, entries start in the firewall.log again.
Also, on the client end, if I try and ping a website on the internet, I get a DNS name resolution, but all dropped packets, and ICMP is blocked again by the sfilter in the firewall.
If on the client end I ping the NS server, then it all starts working.
If on the client end I disable the NIC, then restart it, it starts working.
The NS server is aways on. Only the LAN clients get shutdown at the end of the day.
State:Started Tue Feb 19 16:29:37 GMT 2019 from /etc/shorewall/ (/var/lib/shorewall/firewall compiled Tue Feb 19 16:29:36 GMT 2019 by Shorewall version 5.1.10.2)