Thanks for your reply Fred.

On Mon, 21 Jun 1999, Fred Viles wrote:

> On 21 Jun 99, at 12:23, Rod Moffitt wrote about
>     "[Masq]  Masq&Diald: When 'initial' ":
> 
> | Masq&Diald: When 'initial' traffic that brings up link is UDP kernel DOES
> | not masq - it merely forwards...
> 
> I don't see any evidence of that.

I am getting packets being denied on the OUT path of my ppp0 interface,
ie 'fw-out deny ppp0'. If they were being masquerading or interface to
interface forwarded then 'fw-out' would be changed to 'fw-fwd'. Therefore
the kernel is not observing my request to have masquerading on all packets
from the 'private' machine.

> 
> |...
> | Now Masquerading did work for all packet types from the firewall machine.
> 
> When you run from the firewall machine, you are not using masquerade 
> at all.

All the firewall machine knows is 'what are the source addresses' to
masquerade from and 'what interface' to masquerade over. Therefore as long
as the firewall machine lies within 'what are the source addresses' the
kernel will masquerade them to. I am able to use lynx or ftp to internet
sites no problem from any firewall with masquerading.


> |...
> | Anyone have an idea?
> | 
> | Jun 19 20:12:32 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61232 A.B.C.D:53 
>L=65 S=0x00 I=4096 F=0x0000 T=31
> | Jun 19 20:12:47 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61233 E.F.G.H:53 
>L=65 S=0x00 I=4352 F=0x0000 T=31
> | Jun 19 20:13:02 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61232 A.B.C.D:53 
>L=65 S=0x00 I=4608 F=0x0000 T=31
> | Jun 19 20:13:22 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61233 E.F.G.H:53 
>L=65 S=0x00 I=4864 F=0x0000 T=31
> 
> W.X.Y.Z is your public IP, right?  So the packets are being properly 
> masqueraded, but they are then rejected by your *output* filter.

No - W.X.Y.Z is the Win95 host (behind the firewall with
masquerading) trying to do a DNS lookup on some internet
DNS server at A.B.C.D and E.F.G.H.

> 
> | Here are my masquerading rules:
> | 
> | ipfwadm -F -f
> | ipfwadm -F -p deny
> | 
> | echo "masquerade-forwarding from $PRIVATE_NET"
> | ipfwadm -F -a accept -m -W $PUBLIC_INT -S $PRIVATE_NET
> | 
> | echo "masquerade-forwarding on $DIALD_INT from $PRIVATE_NET"
> | ipfwadm -F -a accept -m -W $DIALD_INT -S $PRIVATE_NET
> | 
> | ipfwadm -F -a deny -o
> 
> What is $PUBLIC_INT -vs- $DIALD_INT?  More important, what are your 
> output rules?

When using diald you have a 'virtual' interface called 'sl0' (ie slip)
that is used to 'detect' traffic - upon which it will bring up the 'real'
link, this case 'ppp0'. I have to masquerade across both since  diald
switches over traffic to the ppp0 from it's sl0.


> 
> - Fred Viles <mailto:[EMAIL PROTECTED]>
> 
> 
> 

--

============ Geek Technology at its best: http://nuked.org ===============
``````````````````````````````````````````````````````````````````````````
Rod Moffitt  ICQ# 6696644    Linux: multi-platform, multi-tasking,
[EMAIL PROTECTED]                multi-user, fast & free! http://www.linux.org
PGP RSA KeyID 570A0731       Protect your privacy!     http://www.pgpi.com
http://rodmoffitt.org        Net, s/w & h/w consulting: http://vissitt.com
..........................................................................
========= Where loved ones are remembered: http://memoriam.org ===========

         Last yeer I kudn't spel Engineer.  Now I are won.





_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to