Thanks for your reply Fred. On Mon, 21 Jun 1999, Fred Viles wrote: > On 21 Jun 99, at 12:23, Rod Moffitt wrote about > "[Masq] Masq&Diald: When 'initial' ": > > | Masq&Diald: When 'initial' traffic that brings up link is UDP kernel DOES > | not masq - it merely forwards... > > I don't see any evidence of that. I am getting packets being denied on the OUT path of my ppp0 interface, ie 'fw-out deny ppp0'. If they were being masquerading or interface to interface forwarded then 'fw-out' would be changed to 'fw-fwd'. Therefore the kernel is not observing my request to have masquerading on all packets from the 'private' machine. > > |... > | Now Masquerading did work for all packet types from the firewall machine. > > When you run from the firewall machine, you are not using masquerade > at all. All the firewall machine knows is 'what are the source addresses' to masquerade from and 'what interface' to masquerade over. Therefore as long as the firewall machine lies within 'what are the source addresses' the kernel will masquerade them to. I am able to use lynx or ftp to internet sites no problem from any firewall with masquerading. > |... > | Anyone have an idea? > | > | Jun 19 20:12:32 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61232 A.B.C.D:53 >L=65 S=0x00 I=4096 F=0x0000 T=31 > | Jun 19 20:12:47 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61233 E.F.G.H:53 >L=65 S=0x00 I=4352 F=0x0000 T=31 > | Jun 19 20:13:02 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61232 A.B.C.D:53 >L=65 S=0x00 I=4608 F=0x0000 T=31 > | Jun 19 20:13:22 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61233 E.F.G.H:53 >L=65 S=0x00 I=4864 F=0x0000 T=31 > > W.X.Y.Z is your public IP, right? So the packets are being properly > masqueraded, but they are then rejected by your *output* filter. No - W.X.Y.Z is the Win95 host (behind the firewall with masquerading) trying to do a DNS lookup on some internet DNS server at A.B.C.D and E.F.G.H. > > | Here are my masquerading rules: > | > | ipfwadm -F -f > | ipfwadm -F -p deny > | > | echo "masquerade-forwarding from $PRIVATE_NET" > | ipfwadm -F -a accept -m -W $PUBLIC_INT -S $PRIVATE_NET > | > | echo "masquerade-forwarding on $DIALD_INT from $PRIVATE_NET" > | ipfwadm -F -a accept -m -W $DIALD_INT -S $PRIVATE_NET > | > | ipfwadm -F -a deny -o > > What is $PUBLIC_INT -vs- $DIALD_INT? More important, what are your > output rules? When using diald you have a 'virtual' interface called 'sl0' (ie slip) that is used to 'detect' traffic - upon which it will bring up the 'real' link, this case 'ppp0'. I have to masquerade across both since diald switches over traffic to the ppp0 from it's sl0. > > - Fred Viles <mailto:[EMAIL PROTECTED]> > > > -- ============ Geek Technology at its best: http://nuked.org =============== `````````````````````````````````````````````````````````````````````````` Rod Moffitt ICQ# 6696644 Linux: multi-platform, multi-tasking, [EMAIL PROTECTED] multi-user, fast & free! http://www.linux.org PGP RSA KeyID 570A0731 Protect your privacy! http://www.pgpi.com http://rodmoffitt.org Net, s/w & h/w consulting: http://vissitt.com .......................................................................... ========= Where loved ones are remembered: http://memoriam.org =========== Last yeer I kudn't spel Engineer. Now I are won. _______________________________________________ Masq maillist - [EMAIL PROTECTED] http://tiffany.indyramp.com/mailman/listinfo/masq Admin requests can be handled by web (above) or [EMAIL PROTECTED]
