/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
"Jose M. Sanchez" wrote:
>
> "Jose M. Sanchez" wrote:
> Aha!
>
> nslookup SHOULD resolve the IP, it doesn't because BIND cannot perform a
> reverse lookup for 192.168.0.1 and it's DNS.
>
> This -NEEDS- to be fixed.
>
> ...
>
> You must have a zone definition in /etc/named.conf for
> 0.0.168.192.IN-ADDR.ARPA, I'll bet you have one for 0.168.192.IN-ADDR.ARPA
> but not the former.
>
> Use Linuxconf to make one, then you'll need to check/modify the
> corresponding file...
I'm using Debian, not redhat or a derivative. I was unable to locate any
"linuxconf" utility on my installation. Can you suggest a more generic
approach?
> After the header record you should have a line which reads
> @ IN NS your.nameserver.com
>
> but remember that "your.nameserver.com" must correspond to the "internal"
> eth0 definition... in other words Linux gives a "name" to each interface,
> separate from but sometimes used interchangeably with, the hostname...
You mean other than eth0 or eth1? I know localhost is a synonym for
127.0.0.1, but what are they for eth0 and eth1?
> You can add an additional record for the "other" interface... anyway, after
> restarting bind, this should get nslookup resolving it's own interface/ns
> name.
>
> This is important, or else your machines will not work.
Thanks. I'll see if I can figure it out for debian and test it out. Any
suggestions?
> -----
>
> > If you are using the DHCP CLIENT in Linux, make sure that it is properly
> > modifying the /etc/resolv.conf file every time you boot up your computer.
>
> Actually, and this may be the source of my problem, what I've been doing is
> setting up DHCP on the windows machine, allowing it to do all the DHCP
> stuff, then using winipconfig to get all of the addresses. Then I set up
> networking on the linux box to match all of the settings (including the MAC
> address) and switch it so that the linux box is connected to the cable
> modem. As far as the linux box is concerned and as long as DHCP doesn't try
> to change my IP, I have a temporarily static IP. Then I change windows
> network setting to the "internal" network settings and reboot. I think this
> is working, because from the linux box out to the internet, everything seems
> fine.
>
> ---
>
> Good grief!
>
> That's pretty ugly.
Acually, it's not too bad. My IP hasn't changed for weeks, so I effectively
have a static IP. I wanted to try it as a static IP before I set up DHCP to
eliminate one variable from the equation. Once I have it working as a
"static" IP I'll set up DHCP, unless you think that's a bad idea?
> I just did a Mandrake 7.0 install for a cable modem (for someone else).
As I said above, I'm using Debian. I'd prefer to stick with it unless you
highly recommend Mandrake or Redhat. It's just that I've spent all this
time downloading a Debian distribution and burning it to a CD (even over a
cable modem it takes quite a while).
> It was really easy. The key was, that by default Linux will only deal with
> the FIRST Ethernet card it probes for.
I've heard that one before. Linux seemed to have no problem setting up both
my cards right away when the "tulip" driver module is loaded.
> You need to set up eth0 to talk to your cable modem, and grab it's IP via
> dhcp (client, not server!). The scripts will take care of everything for
> you.
What scripts?
> THEN using Linuxconf add the second interface, note that I noticed that
> Linuxconf has a problem with multiple adapters. When you go back to edit
> things it might list the second adapter's I/O address and IRQ in the
> first's. I.E.
>
> x0300,x320 etc.
>
> EVERYTIME you edit anything "around" the interface cards in Linuxconf, you
> have to fix this or else it screws things up.
>
> Anyway, at boot eth0 get's it's IP from the Cable Modem and automatically
> modifies resolv.conf... One minor problem is that insists in making your
> machine part of your ISP's domain.
>
> I ended up leaving things this way, I just changed the hostname/domain name
> to reflect what the ISP was doling out... (remember this too, if you are
> running Apache...)
Hmmm, you can't have two hostnames/domains? It is effectively a router
after all, isn't it?
> Let Linuxconf bring up the second interface for you. (THIS IS IMPORTANT!) I
> inadvertently had it coming up via /etc/module. Modprobe was giving me fits.
Hmm... I'm using modprobe. Exactly what problems was it giving you? As I
said above, I'm not using linuxconf...
> Someone on the list suggested that this might be the case, and voila...
> everything worked. Linuxconf brings up the interface for you during the
> latter part of the boot... this in turn makes all the RH/Mandrake/Linuxconf
> scripts work properly and makes doing this a snap. Just fill in the forms...
> just watch out for the above bugaboos...
>
> Mandrake 7.02 might have fixed this, but I haven't tried installing it
> yet... (I just downloaded the ISO yesterday...)
Hmm... maybe I should just use Mandrake. How big is the 7.02 distribution?
> Something is amiss here.
>
> Even with NO DNS running you should be able to get to web pages via IP's.
>
> The exception to this would be if the web page starts by redirecting you...
> this may cause a problem. I temporarily disabled bind just to see...
>
> http://206.132.41.203 (Red Hat's site) ironically did not work, since it
> immediately redirects you...
>
> However
>
> http://207.46.130.45 (at Microsoft)
>
> Works fine because there is no redirection or retrieval from other
> servers...
>
> It brings up the web page with NO DNS access whatsoever...
>
> Try the above. If Microsoft's site does not work, you have a problem with
> Masq (or did you remember to enable ROUTING!!! Even though there is no route
> defined in Linuxconf, you -MUST- turn on the checkbox in the dialog box, or
> masq will fail...)
Nope, doesn't work. Even tried the very "basic" masq setup you suggest
below...
> > Are your Windows machines pointing at your ISPs or your Linux box for DNS
> > resolution? You might want to set up a caching nameserver, and point your
> > Winblows machines at your Linux box... (remember to ENABLE your ethernet
> > card's ability to resolve... you use...)
> >
> > Until you have some sort of resolver/DNS running Linux will NOT resolve
> > addresses for your Masq'd clients...
>
> As I said above, I've tried it both ways... I'm running BIND/named.
>
> ---
>
> If your Winblows machines are pointed at the ISP's DNS for name resolution,
> they should be working. Start here, since this eliminates BIND altogether
> from the picture...
>
> Masq can do it's job. All requests should be sent up to the ISP and back to
> the winblows machine... If I disable BIND and do this myself, it works.
>
> Sounds like you have more than one thing misconfigured.
>
> Check out that routing checkmark! Where you enter your default gateway for
> your machine, this should be empty (since this machine is the router) and
> the "enable routing" must be turned on...
>
> Masq will fail otherwise.
Hmm... Again, I'm not using Linuxconf, so there's no checkbox to check.
> No portmapping -should- not come into play... BUT to play it safe (just in
> case)
> add lines to /etc/hosts.allow which read...
>
> ALL:LOCAL
> ALL:192.168.0.0/255.255.255.0
>
> and change "ALL: PARANOID" to read "portmap: ALL" in /etc/hosts.deny.
>
> Also make the rc.filewall script -NOT- execute at boot.
>
> Reboot and try typing in manually.
>
> /sbin/ipchains -P forward DENY
> /sbin/ipchains -A forward -j MASQ -s 192.168.0.0/24 -d 0.0.0.0/0
>
> This is Masq at it's simplest...
Tried all above, no difference...
> Make sure you network is up...
>
> ipconfig
You mean ifconfig? It's set up...
> and then try accessing a web page from your Windows boxes... preferably the
> Microsoft Site I listed.
Nope, doesn't work...
> I take it that you have added something like
>
> /sbin/depmod -a
> /sbin/modprobe ip_masq_raudio
> /sbin/modprobe ip_masq_irc
> /sbin/modprobe ip_masq_cuseeme
> /sbin/modprobe ip_masq_vdolive
> /sbin/modprobe ip_masq_quake
> /sbin/modprobe ip_masq_ftp
> /sbin/modprobe ip_masq_user
> /sbin/modprobe ip_masq_autofw
> /sbin/modprobe ip_masq_portfw
> /sbin/modprobe ip_masq_mfw
> /sbin/modprobe ip_masq_icq
> #/sbin/modprobe ip_alias
> #/sbin/modprobe rarp
>
> to your /etc/rc.local
>
> You might not have all those modules, depending on your revision, but you
> need to load at least a few for Masq to work.
Yup, there being loaded in init scripts, just not /etc/rc.local (since I'm
not using RH/Mandrake)
> Directly into the second interface on the Linux box.
>
> Eek, under RH 6.1 and Mandrake it should really be set up on eth0 not eth1.
>
> eth1 = second interface
Sorry I misspoke (mistyped?). It's actually connected to eth0...
> Bringing up the interface should create a route entry for the local networks
> on "each side".
>
> the "default * 0.0.0.0 U 1 0 " etc. shows up as a default
>if you've enabled
> routing... (which is a must).
>
> Effectively Linux says... Hmm. I don't see a gateway to 0.0.0.0 (the rest of
> the world) soooo... -I- must be it!
Okay... That makes sense...
Thanks Again,
Bob
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.