>Here is what I have in place now that doesn't seem to work:
Rich.. hehe.. you have been seriously misled here...
>echo "Starting IP Forwarding"
>ipfadm -F -p deny
>ipfwadm -F -a m -S 192.168.1.0/24 -D 0.0.0.0/0
This is fine but should be loaded LAST (purely for security reasons)
They way IPFWADM and IPCHAINS works is that the first rule that
matches up will be run and the rest will be IGNORED. With that in
mind:
># Reject and log static IP machines and block access to anywhere.
>ipfwadm -I -a reject -V 192.168.1.1 -S 192.168.1.72/32 -D 0.0.0.0/0 -o
>ipfwadm -I -a reject -V 192.168.1.1 -S 192.168.1.73/32 -D 0.0.0.0/0 -o
>ipfwadm -I -a reject -V 192.168.1.1 -S 192.168.1.74/32 -D 0.0.0.0/0 -o
>ipfwadm -I -a reject -V 192.168.1.1 -S 192.168.1.75/32 -D 0.0.0.0/0 -o
Since these are your first rules, -ALL- traffic from .1.72-75 will NOT be
able to create ANY traffic. The end. They will be DEAD. If you want to
explictly allow only some traffic from them, explictly mention some
traffic that they CAN do first and then deny them. Like this only for
WWW traffic:
ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.72/32 -D 0.0.0.0/0 www
ipfwadm -I -a reject -V 192.168.1.1 -S 192.168.1.72/32 -D 0.0.0.0/0 -o
># Allow static IP machines. Going anywhere on the local network is valid.
>ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.72/32 -D 192.168.1.0/24
>ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.73/32 -D 192.168.1.0/24
>ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.74/32 -D 192.168.1.0/24
>ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.75/32 -D 192.168.1.0/24
Again.. put this above the above REJECTs.
># Allow static IP machines. Going to www.crmetroymca.org is valid.
>ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.72/32 -D 206.26.71.24/32
>ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.73/32 -D 206.26.71.24/32
>ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.74/32 -D 206.26.71.24/32
>ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.75/32 -D 206.26.71.24/32
This is kinda like my example but you aren't limiting the TYPE of
traffic like my example did.
--David
.----------------------------------------------------------------------------.
| David A. Ranch - Linux/Networking/PC hardware [EMAIL PROTECTED] |
!---- ----!
`----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----'
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]