Although I wouldn't ordinarily consider port fowarding to be a good topic
for this list, the guy who wrote ipportfw referred me to this list when I
e-mailed him directly.  I'm also the kind of guy who does a *lot* of
looking for information on the web before posting to a mailing list.  There
doesn't seem to be much port forwarding information at all, and I haven't
had a bit of luck finding references to my types of problems.

1) We have an internal subnet (10.1.1.x), and our Linux gateway is the only
machine with an external interface.  We have an internal web server, to
which we're routing all port 80 traffic.  It seems to be working great,
with one exception.  Although the internal clients with 10.1.1.x addresses
can hit any external IP address, thanks to IP masquerading, they cannot hit
the web server using the external address (which is actually the address of
the Linux server, which forwards the packets to an internal server).
Perhaps this is some sort of conflict, because their packets are rewritten
by IP masquerading as coming from the same address that they're going to.
Does that make sense?  Is there a way around this?  It's causing problems
with our DNS resolution, because the people inside the firewall have to use
a different address when their inside vs. outside.

2) My other question is about pinging, not because we need to do a lot of
pinging, but because it's sort of a universal test for connectivity.  It's
intriguing that our internal clients cannot ping external hosts with port
forwarding in the kernel, but they could before we compiled port forwarding
in.  I've gone back and forth between the kernels, and I believe that's the
difference.

Of course, the port forwarding question is my greatest concern, because
pinging seems to be our only problem and nothing else seems to have been
affected.  For your viewing pleasure, I now include the script that sets up
ipfwadm and ipportfw.

################################################################
ipfwadm -I -f
ipfwadm -O -f
ipfwadm -F -f
ipfwadm -F -p deny
ipfwadm -F -a masquerade -S 10.1.1.35/24 -D 0.0.0.0/0
ipfwadm -I -a deny -P all -V 209.195.24.6 -S 10.1.1.0/24 -D 0.0.0.0/0

ipportfw -C

ipportfw -A -t209.195.24.4/80 -R 10.1.1.39/80
ipportfw -A -t209.195.24.4/443 -R 10.1.1.39/443
ipportfw -A -t209.195.24.4/21 -R 10.1.1.39/21
ipportfw -A -u209.195.24.4/525 -R 10.1.1.39/525

ipportfw -A -t209.195.24.3/80 -R 10.1.1.37/80
ipportfw -A -u209.195.24.3/525 -R 10.1.1.37/525

ipportfw -A -t209.195.24.5/80 -R 10.1.1.38/80
ipportfw -A -t209.195.24.5/1352 -R 10.1.1.38/1352
ipportfw -A -u209.195.24.5/525 -R 10.1.1.38/525

ipportfw -A -t209.195.24.6/1352 -R 10.1.1.36/1352
ipportfw -A -t209.195.24.6/80 -R 10.1.1.38/80
ipportfw -A -u209.195.24.6/525 -R 10.1.1.36/525
################################################################

Any assistance would be greatly appreciated.

Thanks,
John Ingram





_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to