/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */



Thanks for your reply David.

On Thu, 24 Jun 1999, David A. Ranch wrote:

> >I checked the How-to and FAQs (BTW the masq mailing list archives are NOT
> >searchable - this would be a real time saver). When scanning the diald FAQ
> >(http://www.loonie.net/~eschenk/diald/diald-faq-6.html#ss6.11) it says
> >that TCP connections are not to be used 'to bring up the link' yet UDP are
> 
> This is not what I've seen in the past but I haven't used Diald in a year
> or two.  Either TCP or UDP would bring the link up.

I think Mike is on the right track - about having masquerading
enabled on both the slip and ppp links. UDP and TCP do bring the link up,
however when diald 'switches' over the traffic to the ppp interface, once
it is up the packets are already masqueraded and therefore they get
masqueraded again.

> >Jun 19 20:12:32 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61232
> A.B.C.D:53 L=65 S=0x00 I=4096 F=0x0000 T=31
> >Jun 19 20:12:47 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61233
> E.F.G.H:53 L=65 S=0x00 I=4352 F=0x0000 T=31
> >Jun 19 20:13:02 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61232
> A.B.C.D:53 L=65 S=0x00 I=4608 F=0x0000 T=31
> >Jun 19 20:13:22 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61233
> E.F.G.H:53 L=65 S=0x00 I=4864 F=0x0000 T=31
> 
> Sorry rod but this is worthless without some form of a key.
> Is W.X.Y.Z your internal IPs?  Since I see that the port #s are
> in the high range, it seems like they are MASQed.  Also, since
> this is a OUTPUT deny (should be a reject), that means that
> you already passed through the INPUT and FORWARD stages.

I had the 'key' in the original email - it's possible that you read a
reply from someone without the key included - here it is:

 merely forward the packets out! Take a look at a snapshot of the
 following kernel logs (W.X.Y.Z is the address of the Win95 host, A.B.C.D
 and E.F.G.H are addresses of DNS hosts) where DNS packets where not
 properly Masqueraded, instead they were merely forwarded.

> 
> >echo "masquerade-forwarding from $PRIVATE_NET"
> >ipfwadm -F -a accept -m -W $PUBLIC_INT -S $PRIVATE_NET
> >
> >echo "masquerade-forwarding on $DIALD_INT from $PRIVATE_NET"
> >ipfwadm -F -a accept -m -W $DIALD_INT -S $PRIVATE_NET
> 
> 
> This strikes me ODD.  I understand that you need to point your traffic
> to the SLIP interface but I don't thing you need to do this to BOTH
> interfaces like this.

Yup - totally agree - see comment above...

- Rod

--

============ Geek Technology at its best: http://nuked.org ===============
``````````````````````````````````````````````````````````````````````````
Rod Moffitt  ICQ# 6696644    Linux: multi-platform, multi-tasking,
[EMAIL PROTECTED]                multi-user, fast & free! http://www.linux.org
PGP RSA KeyID 570A0731       Protect your privacy!     http://www.pgpi.com
http://rodmoffitt.org        Net, s/w & h/w consulting: http://vissitt.com
..........................................................................
========= Where loved ones are remembered: http://memoriam.org ===========

         Last yeer I kudn't spel Engineer.  Now I are won.























_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/

Reply via email to