/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Marcos Pinto wrote:

> The problem is that the Windows clients are not being
> able to use any ip service (like web, telnet, ftp
> ....). We've followed the instructions in the
> ip-masquerading faq and other sources, and used the
> following commands to enable it:
>
> /sbin/ipchains -P forward DENY
> /sbin/ipchains -A forward -s 192.168.1.0/24 -j MASQ

Unlike the FAQ I always specify the interface that is to be used for
forwarding the packets.  I've too many connections and masqing all
interfaces makes debugging a pain.

assuming eth0=200.250.x.x and eth1=192.168.1.x
/sbin/ipchains -A forward -i eth0 -s 192.168.1.0/24 -j MASQ

> However, the ping command does work to reach any
> Internet address from the Windows hosts. There's also
> a strange detail: the traceroute output from the
> Windows clients shows no response from the Portmaster.
> I think this has something to do with the problem but
> I didn't get the relation.
>
> Does anybody have an idea on what could be the problem
> ? We're really stuck here.

Whistling in the dark here. :)

Verify the settings in /etc/sysconfig/network
NETWORKING=yes
FORWARD_IPV4=true

What does the routing look like for the linux box?

What other ipchains rules are in effect? [did you accidentally block input
or output for the windows lan for udp and tcp even though you have enabled
forwarding? Remember the packets being forwarded must first go through the
input chain, then the forward chain and finally the output chain.]

What are the default gateway and dns settings on the windows machines?

Lourdes

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to