/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


I'm attempting to solve a problem of Domain authentication/resolution.

My local network which sits behind a ipchains firewall doing NAT via MASQ
works great.  We however are now attempting to join another domain locate
remotely.  Via lmhosts files, WINS entries, etc we can map drives to the new
domain, but we've never been able to browse, nor see the domain when trying
to add accounts under NT.  

We've attributed the problem to the NAT not allowing us resolution on UDP
port 135-139.  UDP being a connectionless protocol just gets lost trying to
come back in the router.

We've implemented ipmasqadm portfw to see if this will help.  I've entered
in the following to open up things for a machine to get out:

/usr/sbin/ipmasqadm -portfw -a -P udp -L xx.xx.xx.xx 135 -R yy.yy.yy.yy 135
/usr/sbin/ipmasqadm -portfw -a -P tcp -L xx.xx.xx.xx 135 -R yy.yy.yy.yy 135
/usr/sbin/ipmasqadm -portfw -a -P tcp -L xx.xx.xx.xx 137 -R yy.yy.yy.yy 137
/usr/sbin/ipmasqadm -portfw -a -P udp -L xx.xx.xx.xx 138 -R yy.yy.yy.yy 139
/usr/sbin/ipmasqadm -portfw -a -P udp -L xx.xx.xx.xx 139 -R yy.yy.yy.yy 139
 
where xx represents the remote PDC, and yy represents my test machine.

In doing a /usr/sbin/ipmasqadm -protfw -l, I see that it resolves the
destination correctly.

First question:  Any ideas why I still can't see the remote domain to try
and log on?
Second question: Is it possible to follow ipchains lead with a line like
this to cover all local hosts:

/usr/sbin/ipmasqadm -portfw -a -P udp -L xx.xx.xx.xx 135:139 -R yy.yy.yy.0
135:139
where yy in this case is the entire subnet.

Thanks,
-Brian

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to