>Here is the map:
>linux external:  to cable modem
>linux internal:   10.0.0.221
>Win 98:     10.0.0.223
>cisco 770 :  10.0.0.254   routing on demand 10.10.10.0/24 to 10.10.10.254


So is the Cisco 770 router on its own ethernet interface in the Linux box 
or is it just on a hub shared with the Win98 box?  

I would recommend to:

        - first, re-address the Cisco to be on the 10.10.10.x network.
          Why?  Since your internal LAN is on a 10.0.0.x network, the
          Win98 machine will use its default gateway to get to a
          10.10.10.x network (a different address than the local 
          10.0.0.x).  This isn't what you want.

        - second, connect the Cisco 770 router to its own ethernet 
          NIC in the Linux box and then add a "route" statement in
          the Linux box to point to the 10.10.10.x network.

          Once the Linux box has its own route to the 10.10.10.x
          network, you can simple FORWARD traffic to the Cisco router
          instead of having to masq it.




>So, with a TCPDUMP, I have monitored my eth0 and discovered that many
>10.x.x.x ip addresses respond to the ping.

Another reason change your local addressing scheme.


>1) do I have a hole in my firewall?   I enclose my rc.firewall script.  I
>thought I was allowing only 10.0.0.0/24 out

Your default input/output policies are ACCEPT!  This is BAD.  Change them
to REJECT.  Be warned, once you do this, is will expose any failures
in your firewall ruleset.


>2) Why do I get so many successful pings when I try 10.x.x.x?  (10.0.1.1,
>10.0.8.1, 10.10.10.1, etc.)

I also have a cablemodem and @Home has hosts on the 10.x.x.x, 192.168.x.x, 
and 172-16-31.x.x.  


>######     Is the following a good idea   ????
>
># let only ping_reply and host unreachable from outside to pass
>###/sbin/ipfwadm -I -P icmp -a accept -S 0/0 0 3 11 -W eth0
>/sbin/ipfwadm -I -P icmp -a accept -S 0/0        -W eth0

Yes.. let ICMP through.  Actually, don't block ICMP at ALL.


># warning: the following line, instead of the one below, opens everything,
>but ineed it to test netcom
>/sbin/ipfwadm -I -a accept -P all -S 0/0 -D $IPADDR -W eth0
>####/sbin/ipfwadm -I -a accept -P tcp -S 0/0 -D $IPADDR http telnet smtp
>auth domain -W eth0

This rule only applies if you are SERVING http, telnet, smtp, etc.
Regardless, you should explictly allow/deny all traffic through
your rulesets on both the INPUT and OUTPUT filters.  I've caught
some interesting RemoteWinsock traffic this way!


>#Accept http web request from anybody
>####/sbin/ipfwadm -I -a accept -P tcp -S 0/0 -D 24.x.x.x  http auth
>domain -W eth0

This is the SAME ruleset as above.


># deny and LOG all tcp from hosts other than those
># specified in the above lines
>/sbin/ipfwadm -I -a deny -P tcp -S 0/0 -D 0/0 0:1000 -W eth0 -o

That should be 0:1023


># Outgoing, flush and set default policy to deny.
># -----------------------------------------------
>/sbin/ipfwadm -O -f
># default policy deny
>/sbin/ipfwadm -O -p deny
># any source going to local interface is valid
>/sbin/ipfwadm -O -a accept -W lo
>/sbin/ipfwadm -O -a accept -S $IPADDR -D 0/0 -W eth0
># Allows all subnet user to go out
>/sbin/ipfwadm -O -a accept -S 0/0 -D 10.0.0.0/24 -W eth1
># catch all rule, all other outgoing is denied and logged.
>/sbin/ipfwadm -O -a deny -S 0/0 -D 0/0 -o
># Forwarding, flush and set default policy to deny.


Your output rulesets are very weak.  They should be a mirror
reflection of your INPUT rulesets.  For example, if you allow
HTTP traffic -in-, your should explictly allow http traffic
-out- as well.  With rules like this and a default policy of
DENY, you will have a strong ruleset.

--David
.----------------------------------------------------------------------------.
|  David A. Ranch - Linux/Networking/PC hardware         [EMAIL PROTECTED]  |
!----                                                                    ----!
`----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----'


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to