Ryan S. Bringel <[EMAIL PROTECTED]> wrote:
>
> I currently use a Windowz FTP deamon that i am very happy with 
> and would like to continue to use, the problem is that box is now 
> behind the linux firewall. The FTP uses a non-standard port (99) 
> also... Please see below.

You will run into problems with this, because FTP uses multiple
connections for data transfers.  In fact, I guarantee that, after you
get this working, that's what your next question is gonig to be....

There is an experimentail version of the ip_masq_ftp module which
supposedly helps out when running a masqueraded ftp server; the default
one only assists ftp *client* connections, not server.  But I cannot
recall where you get the experimental ip_masq_ftp....

> My Command line to start port forwarding..
> ipmasqadm portfw -a -P tcp -L 24.5.28.113 99 -R 192.168.0.2 99

This is important, and you have done it correctly, as far as I can see.

>    ipchains -A input  -i eth+ -p TCP  \
>              -s any/0 99 \
>              -d 192.168.0.2 99  -j ACCEPT

This is not correct; you are permitting only connections in which the
SOURCE port is 99, and the DESTINATION is also 99.  This is very
unlikely, because in a typical TCP connection, the SOURCE port is a
random number between 1024 and 65535.  To fix this, leave out the "-s"
option entirely; it's not doing you any good.

Your "-d" option also has the wrong IP address.  Remember, a packet
coming in from the Internet will *not* have one of your private IP
addresses on it; it will have your public IP address.  When the packet
is de-masqueraded (and/or port-forwarded), and goes OUT of your firewall
box, only THEN will it have a private-IP in the header.

You really shouldn't use "-i eth+", because each of your ethernet
interfaces is on a completely different network.  You should tailor the
rules on each interface to match/allow/deny the traffic you expect to
see ON THAT INTERFACE.  You will have a much safer firewall that way.
To do this, though, you must think in terms of what that interface
should expect to see, before and after masquerading has taken place, and
where the packet should be coming from, destined to, etc.

> Now when I try to connect.....
> ( LordRaiden )[/etc/rc.d]: ftp
> ftp> open 24.5.28.113 99
> ftp: connect: Connection refused
> ftp>

Is this ftp client running on your masq firewall?  If so, it will not
work, because the packets are originating directly from the system. 
They are not beging forwarded through the system, despite your use of
the external IP address, so they will not pass through the port-
forwarding code.  You must test the connection from outside the masq
box.

> Please help!  Ive run out of ideas!  Ive been on IRC in many chatrooms
> and nobody seesm to know what I can do.

I wonder if I should give this IRC thing a try...

-- 
   [EMAIL PROTECTED] (Fuzzy Fox)      || "Nothing takes the taste out of peanut
sometimes known as David DeSimone  ||  butter quite like unrequited love."
  http://www.dallas.net/~fox/      ||                       -- Charlie Brown


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to