/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */



Nick Urbanik <[EMAIL PROTECTED]> wrote:
>
>         modprobe ip_masq_ftp
>         modprobe ip_masq_raudio
>         ipchains -M -S 7200 10 60
>         ipchains -P forward DENY
>         ipchains -A forward -l -s 172.160.0.1 -j MASQ
> but still no joy.

Does your route table point traffic in the correct direction, both ways? 
Is IP forwarding turned on in /etc/sysconfig/network?

>   1. What is the right way to do it?

What you've got above looks okay, I guess.  Usually you want to specify
a network with -s, rather than just a single IP, but it should work, as
long as that's your IP address.

>   2. What am I doing wrong?

Dunno.

>   3. Why can't I use -l with ipchains -P forward DENY?  Or if I can,
>      how?

You just can't.  :)

You can simply add a catch-all rule at the end of the chain, that denies
and logs the packet.

    ipchains -A forward -j DENY -l

>   4. Why am I seeing nothing logged?

Either because of the above, or because you didn't enable IP forwarding,
so the forward chain doesn't get processed at all.

>   5. Since the modules all load happily, and there are no other error
>      messages when I enter these ipchains commands, I assume the kernel
>      is compiled with the right options.

Sure.

>   6. How can I tell if the kernel is compiled with support for IP
>      masquerade?

You'll find out when the ipchains command fails, I guess.


Some time has passed since your post.  Is it working now?

-- 
   [EMAIL PROTECTED] (Fuzzy Fox)      || "Nothing takes the taste out of peanut
sometimes known as David DeSimone  ||  butter quite like unrequited love."
  http://www.dallas.net/~fox/      ||                       -- Charlie Brown


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/

Reply via email to