/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Thanks I got it, (Mandrake 7.02) and quess what?  Exact same problem.... 
This is sooo frustrating.  I can do all of the "testing" successfully up to
the point where I have to do something more than pinging to the internet.  I
can't browse static IPs (Netscape hangs at "host contacted, waiting for
reply"), I can't ping hostnames (dns lookup fails, either w/ Windows looking
to the Linux box for dns or to the IPS's dns servers), and I can't telnet to
static IP's (I get a login and password prompt, get to "last login was..."
but never get a UNIX prompt, or get a prompt then no response).  Obviously,
I can't browse or telnet to hostnames, because dns doesn't work, and they
didn't work w/ static IPs anyway.  I can do anything from the Linux box, so
I am almost positive that its connection to net is set up correctly.  Here
are the details of the setup:

$ipchains -L
Chain input (policy ACCEPT):
Chain forward (policy DENY):
target     prot opt     source           destination           ports
MASQ       all  ------  192.168.0.2      anywhere              n/a
Chain output (policy ACCEPT):

$ifconfig
eth0      Link encap:Ethernet  HWaddr 00:40:33:A2:D3:53  
          inet addr:24.30.116.38  Bcast:24.30.119.255  Mask:255.255.252.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:12825 errors:5753 dropped:0 overruns:0 frame:0
          TX packets:602 errors:122 dropped:0 overruns:0 carrier:244
          collisions:0 txqueuelen:100 
          Interrupt:11 Base address:0x6000 

eth1      Link encap:Ethernet  HWaddr 00:A0:CC:67:EB:C8  
          inet addr:192.168.0.1  Bcast:192.168.0.255  Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:763 errors:5607 dropped:0 overruns:0 frame:0
          TX packets:381 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100 
          Interrupt:9 Base address:0x6100 

lo        Link encap:Local Loopback  
          inet addr:127.0.0.1  Mask:255.0.0.0
          UP LOOPBACK RUNNING  MTU:3924  Metric:1
          RX packets:127 errors:0 dropped:0 overruns:0 frame:0
          TX packets:127 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0 

$route -n
Kernel IP routing table
Destination   Gateway       Genmask         Flags Metric Ref  Use Iface
192.168.0.1   0.0.0.0       255.255.255.255 UH    0      0      0 eth1
24.30.116.38  0.0.0.0       255.255.255.255 UH    0      0      0 eth0
192.168.0.0   0.0.0.0       255.255.255.0   U     0      0      0 eth1
24.30.116.0   0.0.0.0       255.255.252.0   U     0      0      0 eth0
127.0.0.0     0.0.0.0       255.0.0.0       U     0      0      0 lo
0.0.0.0       24.30.116.1   0.0.0.0         UG    0      0      0 eth0


After attempting failed operations from the MASQ'd computer (things w/ dns
lookup, http, telnet, etc), I get the following:

$ipchains -M -L
IP masquerading entries
prot expire   source       destination          ports
TCP  14:02.17 192.168.0.2  207.46.130.45        1037 (61036) -> www
UDP  04:56.00 192.168.0.2  lsray01.we.mediaone.net 1041 (61040) -> domain
TCP  14:47.81 192.168.0.2  cegt201.bradley.edu  1039 (61038) -> telnet
UDP  03:25.26 192.168.0.2  lsray01.we.mediaone.net 1033 (61031) -> domain
UDP  03:08.10 192.168.0.2  lsray01.we.mediaone.net 1032 (61030) -> domain
UDP  04:41.44 192.168.0.2  lsray01.we.mediaone.net 1040 (61039) -> domain
UDP  04:22.43 192.168.0.2  lsray01.we.mediaone.net 1038 (61037) -> domain
UDP  04:03.37 192.168.0.2  lsray01.we.mediaone.net 1036 (61035) -> domain
UDP  04:03.40 192.168.0.2  clnms01.we.mediaone.net netbios-ns (61034) ->
domain
UDP  03:44.31 192.168.0.2  lsray01.we.mediaone.net 1035 (61033) -> domain
UDP  03:27.12 192.168.0.2  lsray01.we.mediaone.net 1034 (61032) -> domain

$ipchains -L -v
Chain input (policy ACCEPT: 2458 packets, 234936 bytes):
Chain forward (policy DENY: 0 packets, 0 bytes):
 pkts bytes target prot opt    tosa tosx  ifname mark outsize source     
destination ports
  372 21565 MASQ   all  ------ 0xFF 0x00  any                 192.168.0.2
anywhere    n/a
Chain output (policy ACCEPT: 1131 packets, 106072 bytes):

Which seems to indicate that MASQ is set up properly and that timouts are
not an issue (no packets were denied for forwarding).  Someone alse had
suggested the packet fragmentation might be the problem.  I have noticed
that for the 2.2.14 kernel, IP_ALWAYS_DEFRAGMENT is no longer a
configuration options.  I have noticed that
/proc/sys/net/ipv4/ip_always_defragment exists, but 
$cat /proc/sys/net/ipv4/ip_always_defragment

reports a number that seems to incement w/ MASQ activity.  I tried setting
it to "1" by doing:

$echo "1" > /proc/sys/net/ipv4/ip_always_defragment

But that didn't seem to fix it.  (I even saw it have a value of -1 once,
that was really weird.)

Does the Winblows settings for "hostname" and "domain" in the DNS tab of
TCP/IP setup matter?  I have tried using both the ISP's domain and my
"internal" domain "schmanski.net" (which is in /etc/networks for
192.168.0.0).  I have tried the domain "bschmans" (which is what I use as
the hostname when I connect my Winblows machine directly to the cable modem)
and "enterprise" which is what I have in /etc/hosts for 192.168.0.2.

Also, I noticed you said *not* to define a default gateway (using
Linuxconf), but when I do that, I can't even ping static IPs on the internet
(Windows ping reports "no route to host")...

Any ideas?

Thanks,
Bob Schmanski

> "Jose M. Sanchez" wrote:
> 
> 
> 
> 
> Do yourself a favor.
> 
> 
> 
> Grab Mandrake for 2.00 and install it instead.
> 
> If you have a CD-ROM burner you can even download the more recent 7.02
> version instead.
> 
> It's sooo easy to set up for Cable modems.
> 
> Most of the setup is prompted and interactive.
> 
> -JMS
> 
> [EMAIL PROTECTED]

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to