/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


My initial guess would be that your web server doesn't have a route back to
your masq machine and the
outside world.  Is the www's machine set to have a default gateway of
192.168.100.3 (your masq
machine)?  If it isn't then you need to add a route to the outside world to go
through this machine.

It looks like your syntax is setup correctly, and if you are accepting
everything then packets
shouldn't be rejected.

I hope this helps

--
Daniell Freed
Computer Services
Dewitt, Ross, & Stevens

He who fights with monsters might take care
lest he thereby become a monster.
And if you gaze for long into an abyss,
the abyss gazes also into you.

Beyond Good and Evil
Friedrich Wilhelm Nietzche


Brdnnvall Fredrik KONSULT wrote:

> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
>
> Hi.
> I'm running kernel 2.2.14 and ipchains 1.3.9, 17-Mar-1999 with TrinityOS
> firewall.
> Masquerading works fine but the only thing that don't work is
> portforwarding.
> Configuration:
> eth0 ip 192.168.100.3
> eth1 ip 193.12.49.22 (external interface)
> On this interface I want to portforward www requests to my internal
> webserver 192.168.100.1 but when i telnet to 193.12.49.22 80 from another
> host the connection just waits and then timeouts saying connection refused.
>
> I have removed all the masquerading and stuff to try to isolate the problem
> so now its just forwarding and accepting everything but still this doesn't
> work.
> [root@djuret]# /usr/sbin/ipmasqadm portfw -a -P tcp -L 193.12.49.22 80 -R
> 192.168.100.1 80
> [root@djuret rc.d]# ipmasqadm portfw -l
> prot localaddr rediraddr lport rport pcnt pref
> TCP djuret_ext webben www www 10 10
> [root@djuret rc.d]# ipchains -L
> Chain input (policy ACCEPT):
> Chain forward (policy ACCEPT):
> Chain output (policy ACCEPT):
> tcpdump show this
> 21:10:26.437189 eth1 < 193.12.49.33.1044 > 193.12.49.22.telnet: .
> 771740:771740(0) ack 3154177325 win 8303 (DF)
> 21:10:26.437512 eth1 > 193.12.49.22.telnet > 193.12.49.33.1044: P
1:122(121)
> ack 0 win 32696 (DF)
> 21:10:26.728539 eth1 < 193.12.49.33.1044 > 193.12.49.22.telnet: . 0:0(0)
ack
> 122 win 8182 (DF)
> 21:10:29.745289 eth1 < 193.12.49.33.1061 > 193.12.49.22.www: S
> 2362258:2362258(0) win 8192 <mss 536,nop,nop,sackOK> (DF)
> 21:10:29.745637 eth0 > 193.12.49.33.1061 > 192.168.100.1.www: S
> 2362258:2362258(0) win 8192 <mss 536,nop,nop,sackOK> (DF)
> 21:10:32.628631 eth1 < 193.12.49.33.1061 > 193.12.49.22.www: S
> 2362258:2362258(0) win 8192 <mss 536,nop,nop,sackOK> (DF)
> 21:10:32.628829 eth0 > 193.12.49.33.1061 > 192.168.100.1.www: S
> 2362258:2362258(0) win 8192 <mss 536,nop,nop,sackOK> (DF)
> 21:10:38.627268 eth1 < 193.12.49.33.1061 > 193.12.49.22.www: S
> 2362258:2362258(0) win 8192 <mss 536,nop,nop,sackOK> (DF)
> 21:10:38.627443 eth0 > 193.12.49.33.1061 > 192.168.100.1.www: S
> 2362258:2362258(0) win 8192 <mss 536,nop,nop,sackOK> (DF)
>
> I really don't understand the tcpdump output but somebody have a clue on
> whats going on???
>
> mvh Fredrik
> Email: [ [EMAIL PROTECTED] ]
> or [ [EMAIL PROTECTED] ]
> Webb: [ http://www.imb.se ]
>
> _______________________________________________
> Masq maillist  -  [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS
INCLUDES UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
>
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to