/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Pankaj Arora wrote:
> I've had an IP MASQ server setup for some time now -- it has
> been great.
> Quick question though. I am now also using SMB on that box
> and have a share
> setup. I want to only be able to access the share from within my LAN.
> Password protection is not enough, I want to make it appear
> as if I don't
> even have SMB running on the interface hooked up to my cable
> modem -- I was
> told you can't have SMB running on one interface only, and
If you can't then you can come remarkably close to it. See below.
> the way around it
> is this IP CHAINS rule:
>
> ipchains -A input -i eth1 --dport 139 -p tcp -j REJECT
>
> as where eth1 would be the interface hooked up the the 'net.
> The problem is
> that it locked me out of my SMB share from all interfaces --
> and IPCHAINS -L
> confirmed that.
ipchains works beautifully with samba here. 'ipchains -L' does not give the
whole picture (since it does not list the interfaces) try using 'ipchains -L
input -v' to see the interfaces involved.
Samba uses ports 137 through 139 and I'd recommend using DENY rather than
reject. [I tend set rules to REJECT internal requests but DENY from
external sources. Hate to do it that way since it does not conform to RFC
but it slows down portscanners (since they now have to wait until each
request times out) and I've had much less trouble with scans since I made
the change.]
In my experience if you have more than one interface and do not list the
interface to be used then samba stops listening until you update the config
file. (Actually it picks a single primary interface and only uses it. That
never seems to match the interface I want though.)
Please look at the options for 'hosts allow', 'interfaces' and 'bind
interfaces only'.
Warning: if you use 'bind interfaces only' you must add 127.0.0.1 to
interfaces if you want to be able to use swat or have smbd update passwords.
for example assuming I connect to the internet with eth1 want network
192.168.1.x to be able to connect via eth0 on 192.168.1.254 then I might
use.
/sbin/ipchains -A input -i eth1 --destination-port 137:139 -p tcp -j DENY
[this is far from enough but it's a start.]
and in /etc/smb.conf
--
[global]
hosts allow = 192.168.1. 127.
interfaces = 192.168.1.254/24 127.0.0.1/8
bind interfaces only = yes
...
--
I am using ipchains 1.3.9, samba 2.0.5a and kernel 2.2.14.
Hope this helps,
Lourdes
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.