--- dump-00.txt	2009-03-30 20:29:32.000000000 -0300
+++ dump-10.txt	2009-03-30 20:32:42.000000000 -0300
@@ -1,20 +1,16 @@
-Shorewall 4.2.5 Dump at mistral.cejil.org - Mon Mar 30 20:29:32 ART 2009
+Shorewall 4.2.5 Dump at mistral.cejil.org - Mon Mar 30 20:32:42 ART 2009
 
    Shorewall-perl 4.2.5.3
 
-Counters reset Mon Mar 30 20:27:15 ART 2009
+Counters reset Mon Mar 30 20:32:14 ART 2009
 
 Chain INPUT (policy DROP 0 packets, 0 bytes)
  pkts bytes target     prot opt in     out     source               destination         
-    1    60 ACCEPT     udp  --  vnet0  *       0.0.0.0/0            0.0.0.0/0           udp dpt:53 
-    0     0 ACCEPT     tcp  --  vnet0  *       0.0.0.0/0            0.0.0.0/0           tcp dpt:53 
-    0     0 ACCEPT     udp  --  vnet0  *       0.0.0.0/0            0.0.0.0/0           udp dpt:67 
-    0     0 ACCEPT     tcp  --  vnet0  *       0.0.0.0/0            0.0.0.0/0           tcp dpt:67 
-   29  3008 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0           state INVALID,NEW 
-  333 34878 net2fw     all  --  eth0   *       0.0.0.0/0            0.0.0.0/0           
+    0     0 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0           state INVALID,NEW 
+   30  2280 net2fw     all  --  eth0   *       0.0.0.0/0            0.0.0.0/0           
     0     0 vpn2fw     all  --  tun+   *       0.0.0.0/0            0.0.0.0/0           
     0     0 vms2fw     all  --  vnet+  *       0.0.0.0/0            0.0.0.0/0           
-   77  6804 ACCEPT     all  --  lo     *       0.0.0.0/0            0.0.0.0/0           
+    0     0 ACCEPT     all  --  lo     *       0.0.0.0/0            0.0.0.0/0           
     0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED 
     0     0 Drop       all  --  *      *       0.0.0.0/0            0.0.0.0/0           
     0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:INPUT:DROP:' 
@@ -22,11 +18,6 @@
 
 Chain FORWARD (policy DROP 0 packets, 0 bytes)
  pkts bytes target     prot opt in     out     source               destination         
-    4   304 ACCEPT     all  --  *      vnet0   0.0.0.0/0            10.3.14.0/24        state RELATED,ESTABLISHED 
-    4   304 ACCEPT     all  --  vnet0  *       10.3.14.0/24         0.0.0.0/0           
-    0     0 ACCEPT     all  --  vnet0  vnet0   0.0.0.0/0            0.0.0.0/0           
-    0     0 REJECT     all  --  *      vnet0   0.0.0.0/0            0.0.0.0/0           reject-with icmp-port-unreachable 
-    0     0 REJECT     all  --  vnet0  *       0.0.0.0/0            0.0.0.0/0           reject-with icmp-port-unreachable 
     0     0 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0           state INVALID,NEW 
     0     0 net_frwd   all  --  eth0   *       0.0.0.0/0            0.0.0.0/0           
     0     0 vpn_frwd   all  --  tun+   *       0.0.0.0/0            0.0.0.0/0           
@@ -38,10 +29,10 @@
 
 Chain OUTPUT (policy DROP 0 packets, 0 bytes)
  pkts bytes target     prot opt in     out     source               destination         
-  264 25982 fw2net     all  --  *      eth0    0.0.0.0/0            0.0.0.0/0           
+   23  2852 fw2net     all  --  *      eth0    0.0.0.0/0            0.0.0.0/0           
     0     0 fw2vpn     all  --  *      tun+    0.0.0.0/0            0.0.0.0/0           
-    1    76 fw2vms     all  --  *      vnet+   0.0.0.0/0            0.0.0.0/0           
-   77  6804 ACCEPT     all  --  *      lo      0.0.0.0/0            0.0.0.0/0           
+    0     0 fw2vms     all  --  *      vnet+   0.0.0.0/0            0.0.0.0/0           
+    0     0 ACCEPT     all  --  *      lo      0.0.0.0/0            0.0.0.0/0           
     0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED 
     0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
     0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:OUTPUT:REJECT:' 
@@ -50,10 +41,10 @@
 Chain Drop (9 references)
  pkts bytes target     prot opt in     out     source               destination         
     0     0 reject     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:113 /* Auth */ 
-    4  1400 dropBcast  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
+    0     0 dropBcast  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
     0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 3 code 4 /* Needed ICMP types */ 
     0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 11 /* Needed ICMP types */ 
-    2  1244 dropInvalid  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
+    0     0 dropInvalid  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
     0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 135,445 /* SMB */ 
     0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpts:137:139 /* SMB */ 
     0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:137 dpts:1024:65535 /* SMB */ 
@@ -82,7 +73,7 @@
 
 Chain dropBcast (2 references)
  pkts bytes target     prot opt in     out     source               destination         
-    2   156 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0           ADDRTYPE match dst-type BROADCAST 
+    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0           ADDRTYPE match dst-type BROADCAST 
     0     0 DROP       all  --  *      *       0.0.0.0/0            224.0.0.0/4         
 
 Chain dropInvalid (2 references)
@@ -98,12 +89,12 @@
 
 Chain fw2net (1 references)
  pkts bytes target     prot opt in     out     source               destination         
-  169 19927 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED 
+   18  2472 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED 
     0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           
     0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:22 /* SSH */ 
-   85  5295 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:53 /* DNS */ 
+    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:53 /* DNS */ 
     0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:53 /* DNS */ 
-   10   760 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:123 /* NTP */ 
+    5   380 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:123 /* NTP */ 
     0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:80 /* HTTP */ 
     0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:443 /* HTTPS */ 
     0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:21 /* FTP */ 
@@ -120,7 +111,7 @@
 
 Chain fw2vms (1 references)
  pkts bytes target     prot opt in     out     source               destination         
-    1    76 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED 
+    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED 
     0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           
     0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:22 /* SSH */ 
     0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:53 /* DNS */ 
@@ -157,14 +148,14 @@
 
 Chain net2fw (1 references)
  pkts bytes target     prot opt in     out     source               destination         
-    5  1460 blacklst   all  --  *      *       0.0.0.0/0            0.0.0.0/0           state INVALID,NEW 
-    5  1460 smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           state INVALID,NEW 
-    5  1460 norfc1918  all  --  *      *       0.0.0.0/0            0.0.0.0/0           state NEW 
-  276 23115 tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
-  328 33418 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED 
+    0     0 blacklst   all  --  *      *       0.0.0.0/0            0.0.0.0/0           state INVALID,NEW 
+    0     0 smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           state INVALID,NEW 
+    0     0 norfc1918  all  --  *      *       0.0.0.0/0            0.0.0.0/0           state NEW 
+   26  1976 tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
+   30  2280 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED 
     0     0 reject     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8 /* Ping */ 
     0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           
-    1    60 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:22 /* SSH */ 
+    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:22 /* SSH */ 
     0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:80 /* HTTP */ 
     0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:443 /* HTTPS */ 
     0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:25 /* Mail */ 
@@ -176,9 +167,9 @@
     0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:993 /* IMAPS */ 
     0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:1194 /* OpenVPN */ 
     0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:1194 
-    4  1400 Drop       all  --  *      *       0.0.0.0/0            0.0.0.0/0           
-    2  1244 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:net2fw:DROP:' 
-    2  1244 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0           
+    0     0 Drop       all  --  *      *       0.0.0.0/0            0.0.0.0/0           
+    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:net2fw:DROP:' 
+    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 
 Chain net2vms (1 references)
  pkts bytes target     prot opt in     out     source               destination         
@@ -347,20 +338,19 @@
 
 NAT Table
 
-Chain PREROUTING (policy ACCEPT 7 packets, 1596 bytes)
+Chain PREROUTING (policy ACCEPT 0 packets, 0 bytes)
  pkts bytes target     prot opt in     out     source               destination         
-    7  1596 dnat       all  --  *      *       0.0.0.0/0            0.0.0.0/0           
+    0     0 dnat       all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 
-Chain POSTROUTING (policy ACCEPT 117 packets, 7473 bytes)
+Chain POSTROUTING (policy ACCEPT 5 packets, 380 bytes)
  pkts bytes target     prot opt in     out     source               destination         
-    1    76 MASQUERADE  all  --  *      *       10.3.14.0/24        !10.3.14.0/24        
 
-Chain OUTPUT (policy ACCEPT 117 packets, 7473 bytes)
+Chain OUTPUT (policy ACCEPT 5 packets, 380 bytes)
  pkts bytes target     prot opt in     out     source               destination         
 
 Chain dnat (1 references)
  pkts bytes target     prot opt in     out     source               destination         
-    5  1460 net_dnat   all  --  eth0   *       0.0.0.0/0            0.0.0.0/0           
+    0     0 net_dnat   all  --  eth0   *       0.0.0.0/0            0.0.0.0/0           
 
 Chain net_dnat (1 references)
  pkts bytes target     prot opt in     out     source               destination         
@@ -377,24 +367,24 @@
 
 Mangle Table
 
-Chain PREROUTING (policy ACCEPT 419 packets, 42350 bytes)
+Chain PREROUTING (policy ACCEPT 30 packets, 2280 bytes)
  pkts bytes target     prot opt in     out     source               destination         
-  419 42350 tcpre      all  --  *      *       0.0.0.0/0            0.0.0.0/0           
+   30  2280 tcpre      all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 
-Chain INPUT (policy ACCEPT 411 packets, 41742 bytes)
+Chain INPUT (policy ACCEPT 30 packets, 2280 bytes)
  pkts bytes target     prot opt in     out     source               destination         
 
-Chain FORWARD (policy ACCEPT 8 packets, 608 bytes)
+Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
  pkts bytes target     prot opt in     out     source               destination         
-    8   608 tcfor      all  --  *      *       0.0.0.0/0            0.0.0.0/0           
+    0     0 tcfor      all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 
-Chain OUTPUT (policy ACCEPT 342 packets, 32862 bytes)
+Chain OUTPUT (policy ACCEPT 23 packets, 2852 bytes)
  pkts bytes target     prot opt in     out     source               destination         
-  342 32862 tcout      all  --  *      *       0.0.0.0/0            0.0.0.0/0           
+   23  2852 tcout      all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 
-Chain POSTROUTING (policy ACCEPT 350 packets, 33470 bytes)
+Chain POSTROUTING (policy ACCEPT 23 packets, 2852 bytes)
  pkts bytes target     prot opt in     out     source               destination         
-  350 33470 tcpost     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
+   23  2852 tcpost     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 
 Chain tcfor (1 references)
  pkts bytes target     prot opt in     out     source               destination         
@@ -410,13 +400,12 @@
 
 Conntrack Table
 
-udp      17 111 src=10.3.14.17 dst=91.189.94.4 sport=123 dport=123 packets=4 bytes=304 src=91.189.94.4 dst=94.75.244.29 sport=123 dport=1 packets=4 bytes=304 [ASSURED] mark=0 secmark=0 use=1
-udp      17 2 src=94.75.244.29 dst=80.85.129.103 sport=123 dport=123 packets=1 bytes=76 src=80.85.129.103 dst=94.75.244.29 sport=123 dport=123 packets=1 bytes=76 mark=0 secmark=0 use=1
-udp      17 70 src=127.0.0.1 dst=127.0.0.1 sport=45314 dport=53 packets=2 bytes=120 src=127.0.0.1 dst=127.0.0.1 sport=53 dport=45314 packets=2 bytes=152 [ASSURED] mark=0 secmark=0 use=1
-udp      17 1 src=94.75.244.29 dst=83.137.16.7 sport=123 dport=123 packets=1 bytes=76 src=83.137.16.7 dst=94.75.244.29 sport=123 dport=123 packets=1 bytes=76 mark=0 secmark=0 use=1
-udp      17 74 src=127.0.0.1 dst=127.0.0.1 sport=60027 dport=53 packets=2 bytes=140 src=127.0.0.1 dst=127.0.0.1 sport=53 dport=60027 packets=2 bytes=140 [ASSURED] mark=0 secmark=0 use=1
-udp      17 2 src=94.75.244.29 dst=85.12.29.43 sport=123 dport=123 packets=1 bytes=76 src=85.12.29.43 dst=94.75.244.29 sport=123 dport=123 packets=1 bytes=76 mark=0 secmark=0 use=1
-tcp      6 299 ESTABLISHED src=190.244.95.55 dst=94.75.244.29 sport=55924 dport=22 packets=276 bytes=23115 src=94.75.244.29 dst=190.244.95.55 sport=22 dport=55924 packets=169 bytes=19927 [ASSURED] mark=0 secmark=0 use=1
+udp      17 4 src=94.75.244.29 dst=80.85.129.103 sport=123 dport=123 packets=1 bytes=76 src=80.85.129.103 dst=94.75.244.29 sport=123 dport=123 packets=1 bytes=76 mark=0 secmark=0 use=1
+udp      17 6 src=94.75.244.29 dst=83.137.16.7 sport=123 dport=123 packets=1 bytes=76 src=83.137.16.7 dst=94.75.244.29 sport=123 dport=123 packets=1 bytes=76 mark=0 secmark=0 use=1
+udp      17 4 src=94.75.244.29 dst=62.93.230.13 sport=123 dport=123 packets=1 bytes=76 src=62.93.230.13 dst=94.75.244.29 sport=123 dport=123 packets=1 bytes=76 mark=0 secmark=0 use=1
+udp      17 3 src=94.75.244.29 dst=91.189.94.4 sport=123 dport=123 packets=1 bytes=76 src=91.189.94.4 dst=94.75.244.29 sport=123 dport=123 packets=1 bytes=76 mark=0 secmark=0 use=1
+udp      17 4 src=94.75.244.29 dst=85.12.29.43 sport=123 dport=123 packets=1 bytes=76 [UNREPLIED] src=85.12.29.43 dst=94.75.244.29 sport=123 dport=123 packets=0 bytes=0 mark=0 secmark=0 use=1
+tcp      6 299 ESTABLISHED src=190.244.95.55 dst=94.75.244.29 sport=55924 dport=22 packets=573 bytes=45231 src=94.75.244.29 dst=190.244.95.55 sport=22 dport=55924 packets=386 bytes=97223 [ASSURED] mark=0 secmark=0 use=1
 
 IP Configuration
 
@@ -439,9 +428,9 @@
 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
     link/ether 00:1e:c9:b0:70:e2 brd ff:ff:ff:ff:ff:ff
     RX: bytes  packets  errors  dropped overrun mcast   
-    41670      343      0       0       0       0      
+    71981      673      0       0       0       0      
     TX: bytes  packets  errors  dropped carrier collsns 
-    29520      254      0       0       0       0      
+    113532     503      0       0       0       0      
 3: eth1: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN qlen 1000
     link/ether 00:1e:c9:b0:70:e4 brd ff:ff:ff:ff:ff:ff
     RX: bytes  packets  errors  dropped overrun mcast   
@@ -459,13 +448,13 @@
     RX: bytes  packets  errors  dropped overrun mcast   
     468        6        0       0       0       0      
     TX: bytes  packets  errors  dropped carrier collsns 
-    2642       51       0       0       0       0      
+    7582       146      0       0       0       0      
 6: vnet2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 500
     link/ether 26:1f:34:97:99:a4 brd ff:ff:ff:ff:ff:ff
     RX: bytes  packets  errors  dropped overrun mcast   
     1364       22       0       0       0       0      
     TX: bytes  packets  errors  dropped carrier collsns 
-    3134       57       0       0       0       0      
+    8074       152      0       0       0       0      
 
 Bridges
 
@@ -566,11 +555,11 @@
 ipt_ecn                10112  0 
 ipt_ECN                10496  0 
 ipt_LOG                13700  16 
-ipt_MASQUERADE         10752  1 
+ipt_MASQUERADE         10752  0 
 ipt_NETMAP              9856  0 
 ipt_recent             16028  0 
 ipt_REDIRECT            9856  0 
-ipt_REJECT             11136  4 
+ipt_REJECT             11136  2 
 ipt_ttl                 9728  0 
 ipt_TTL                 9984  0 
 ipt_ULOG               15268  0 
@@ -578,7 +567,7 @@
 nf_conntrack_amanda    11904  1 nf_nat_amanda
 nf_conntrack_ftp       15652  1 nf_nat_ftp
 nf_conntrack_h323      56904  1 nf_nat_h323
-nf_conntrack_ipv4      21900  51 iptable_nat,nf_nat
+nf_conntrack_ipv4      21900  50 iptable_nat,nf_nat
 nf_conntrack_irc       13348  1 nf_nat_irc
 nf_conntrack_netbios_ns    10496  0 
 nf_conntrack_netlink    24320  0 
@@ -622,9 +611,9 @@
 xt_pkttype              9856  0 
 xt_policy              11136  0 
 xt_realm                9600  0 
-xt_state               10112  35 
+xt_state               10112  34 
 xt_tcpmss              10112  0 
-xt_tcpudp              11008  92 
+xt_tcpudp              11008  88 
 xt_time                10752  0 
 
 Shorewall has detected the following iptables/netfilter capabilities:
@@ -688,19 +677,19 @@
 
 Device eth0:
 qdisc pfifo_fast 0: root bands 3 priomap  1 2 2 2 1 2 0 0 1 1 1 1 1 1 1 1
- Sent 28132 bytes 255 pkt (dropped 0, overlimits 0 requeues 0) 
+ Sent 110470 bytes 494 pkt (dropped 0, overlimits 0 requeues 0) 
  rate 0bit 0pps backlog 0b 0p requeues 0 
 
 
 Device vnet1:
 qdisc pfifo_fast 0: root bands 3 priomap  1 2 2 2 1 2 0 0 1 1 1 1 1 1 1 1
- Sent 2694 bytes 52 pkt (dropped 0, overlimits 0 requeues 0) 
+ Sent 7582 bytes 146 pkt (dropped 0, overlimits 0 requeues 0) 
  rate 0bit 0pps backlog 0b 0p requeues 0 
 
 
 Device vnet2:
 qdisc pfifo_fast 0: root bands 3 priomap  1 2 2 2 1 2 0 0 1 1 1 1 1 1 1 1
- Sent 3186 bytes 58 pkt (dropped 0, overlimits 0 requeues 0) 
+ Sent 8074 bytes 152 pkt (dropped 0, overlimits 0 requeues 0) 
  rate 0bit 0pps backlog 0b 0p requeues 0 
 
 
