/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Dmitriy Shishkin <[EMAIL PROTECTED]> wrote:
>
> I'm very concerned about strange ICQ behavior.
This is not strange behavior; this is how ICQ behaves, and why it
requires a protocol module, or port-forwarding, in order to work
properly.
All ICQ clients have the ability to send and receive messages via UDP
through the ICQ servers. However, ICQ recognizes that if everyone did
this, it would not only be a loss of privacy, but also a huge load on
their servers. So, all ICQ clients will first attempt to send the
message directly to the other ICQ client, via TCP, and only fall back to
sending through the server if the TCP connection fails.
The ICQ client chooses a random port number, and tells the ICQ server
about it. Other ICQ clients learn about this port number and attempt a
connection directly to it, but when you are masquerading the client,
they attempt to connect to the masq box, and fail.
When your masq'd ICQ client is the first to attempt to send a message,
the outgoing TCP connection is masqueraded, and works fine, assuming
that no firewall stands in the way of getting to the remote ICQ client.
Once that TCP connection is established, communication will proceed
without problems between the two clients.
If the outside ICQ client is the first to attempt to send, it will fail
trying to connect to your masq box, and so the first message will go
through the server via UDP. Then, when the inside ICQ client responds,
it will set up a TCP connection outbound, and things should still work.
The problem, which you are probably running into, is that there are two
firewalls in place, and neither ICQ client can successfully initiate a
TCP connection to the other. Thus they both waste time trying.
One solution is the ip_masq_icq module:
http://members.xoom.com/djsf/masq-icq/
I have had some problems with this module, though, but once the bugs are
flushed out, it should be the best solution.
You can also set up a port-forwarding solution, which is the next-best
solution. Choose a range of ports, such as 20000-20020, and port-
forward those ports to the particular ICQ client you are setting up.
Then configure that ICQ client, saying it is behind a firewall, and that
it should restrict its port choices to 20000 to 20020. This should keep
things working. However, it has a disadvantage, that you must set up
each individual ICQ client to use a different port-range, so if you have
more than a couple, you won't like this solution.
--
[EMAIL PROTECTED] (Fuzzy Fox) || "Good judgment comes from experience.
sometimes known as David DeSimone || Experience comes from bad judgment."
http://www.dallas.net/~fox/ || -- Life Lessons
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.