Hi everyone,
Sorry if this is an easy one, but I'm out of ideas. I've read the
HOWTO,
I've read the links and I've searched the mailing list archives, but I
cannot seem to fix the problem.
Here is what's happening.
I've set up ip masquerading and firewalling on one of my linux boxes.
I have set up IP aliasing on that box, so that eth0 responds to my
static
IP and eth0:0 responds to 192.168.24.1.
The other boxes behind the firewall, 192.168.24.2 and 192.168.24.3 each
only know about the firewall/gateway and all our connections seem fine.
The problem comes from trying to run Diablo through the firewall. I've
seen various posts on the list saying that people have had success with
Diablo using either ipportfw or ipautofw, but I've tried both and I
can't
even get one of the machines playing successfully. The only hint I have
is from Diablo saying that I "either have a very poor internet
connection
or your ISP is not processing UDP packets." Since we aren't having any
problems playing Q2, or ftp-ing, telnetting, or surfing the web, though
the firewall, I don't believe that adding the firewall has caused that
much of a degradation in the quality of my signal.
Ideally, I want both machines behind the firewall to be able to play
Diablo (on Battle.net, of course, that's what I really mean when I'm
saying "diablo" above) at the same time, but right now I'd be happy to
have just one connecting successfully.
Can anyone offer any suggestions? My system specs and my rc.firewall
are
included below.
Thanks.
--
Joe MacDonald
"When all candles be out, all cats be grey."
John Halloway, Proverbs, 1542
Kernel: 2.0.37
(originally a 2.0.35 with patches applied in the following
order:
+ 2.0.35-2.0.36
+ subs-patch-1.37 (IPPORTFW)
+ portfw-ftp-patch
+ loose-udp-2.0.36
+ ipfwadm-2.3.0
+ 2.0.36-2.0.37
)
my rc.local:
#!/bin/sh
#
# /etc/rc.d/rc.local: Local system initialization script.
#
# Put any local setup commands in here:
# Running gpm
echo "Running gpm..."
gpm -m /dev/mouse -t ms3
# There is another way to run GPM, where it acts as a repeater
outputting
# a virtual MouseSystems mouse on /dev/gpmdata. This is useful for
# feeding gpm's data to X, especially if you've got a busmouse (in that
# situation X and gpm may not coexist without using a repeater). To try
# running a GPM repeater for X, change the gpm command line to look like
# this:
# gpm -R -m /dev/mouse -t ms3
# Then, make sure that the mouse configuration in your XF86Config file
# refers to the repeater device (/dev/gpmdata) and a MouseSystems mouse
# type. If you edit the file directly, you'll want the lines to look
like
# this (minus the comment marks '#' shown here, of course):
#Section "Pointer"
# Protocol "MouseSystems"
# Device "/dev/gpmdata"
echo "Firewalling . . ."
. /etc/rc.d/rc.firewall
and my rc.firewall:
/sbin/depmod -a
echo probing for ip_masq_ftp module . . .
/sbin/modprobe ip_masq_ftp
echo probing for the ip_masq_raudio module . . .
/sbin/modprobe ip_masq_raudio
echo probing for the ip_masq_irc module . . .
/sbin/modprobe ip_masq_irc
echo probing for the ip_masq_quake module . . .
/sbin/modprobe ports=ip_masq_quake 26000,27000,27910
echo turning on IP forwarding
echo "1" > /proc/sys/net/ipv4/ip_forward
echo setting up ipfwadm rules
/sbin/ipfwadm -M -s 7200 10 60
/sbin/ipfwadm -F -p deny
/sbin/ipfwadm -F -a m -S 192.168.24.0/24 -D 0.0.0.0/0
echo setting up ICQ forwarding . . .
/sbin/ipautofw -A -r tcp 2000 4000 -c udp 4000
echo setting up RealAudio forwarding . . .
/sbin/ipautofw -A -r udp 6970 7170 -c tcp 7070
echo setting up battle.net forwarding . . .
/sbin/ipautofw -A -r udp 6112 6112 -c tcp 116
/sbin/ipautofw -A -r udp 6112 6112 -c tcp 118
The results of my ifconfig:
lo Link encap:Local Loopback
inet addr:127.0.0.1 Bcast:127.255.255.255 Mask:255.0.0.0
UP BROADCAST LOOPBACK RUNNING MTU:3584 Metric:1
RX packets:34 errors:0 dropped:0 overruns:0 frame:0
TX packets:34 errors:0 dropped:0 overruns:0 carrier:0
Collisions:0
eth0 Link encap:Ethernet HWaddr 00:60:67:62:0E:7C
inet addr:24.112.131.178 Bcast:24.112.131.255
Mask:255.255.254.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:719571 errors:0 dropped:0 overruns:0 frame:14
TX packets:173055 errors:0 dropped:0 overruns:0 carrier:0
Collisions:17054
Interrupt:5 Base address:0x280
eth0:0 Link encap:Ethernet HWaddr 00:60:67:62:0E:7C
inet addr:192.168.24.1 Bcast:192.168.24.255
Mask:255.255.255.0
UP BROADCAST RUNNING MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
Collisions:0
and my ipportfw -L:
Prot Local Addr/Port > Remote Addr/Port
UDP 24.112.131.178/6112 > 192.168.24.2/6112
TCP 24.112.131.178/118 > 192.168.24.2/118
TCP 24.112.131.178/116 > 192.168.24.2/116
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]