/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Hi, I run into problems when I tried to use portfw in combination with ipmasq to be able to access a internal webserver (www-interface to a windows NT mailserver). Problem: When a wwwclient on the external internet connects to the webserver, only the question: "Do you want to accept a cookie" is dispayed. Then the connection freezes, if you accept the cookie or not.. I appreciate every hint to solve the problem (detailed output of tcpdump below). As far as I understand the problem: The internal www-server sends packets with the "don't fragment" bit set to do MTU discovery. When the packet is too large , the linux box sends according to RFC 1191 a "need to frag" icmp packet and does not frag the packet. But: The linux box sends a "need to frag" -icmp packet 1) on the wrong interface (external instead of internal) and 2) to the wrong host (the packet is sent to the ip- address of the external interface instead of the ip- address of the web-server). Is this a bug in the portfw software? Also hints, how to avoid portfw (can you use a proxy on the linux box, to do this) are welcome. Thanks, Ingmar. Here the scematics of the network: Internet--Cisco---eth0 linux eth1 --- internal webserver The linux box is masquerading the internal net on eth1. I use kernel 2.2.14 with portforwarding enabled and the FreeS/Wan 1.3 -patch included (But at this time no ipsec-related things enabled). The Cisco router is doing ip-over-ip encasulation to tunnel over a third companies network (without the linux box no problems with this). The mtu is set to 1500 on both ethernet interfaces of the linux box. The masquerading and the forwarding is done by ipchains -A forward -j MASQ -i .. -s .. the portforwarding by ipmasqadm portfw .... During the connection attempt I run tcpdump on both interfaces of the linux box. Here the result: The www-server is listening on port 8000, extern.bla.com is the external interface, intern.bla.com the internal interface of the linux box, wwwclient.blub.com the external www-client (on different network), wwwserver.intern.bla.com the www-server on the internal, masqueraded network. Tcpdump on the external interface: 14:01:05.708138 extern.bla.com.8000 > wwwclient.blub.com.1852: . 106045:107505(1460) ack 584053982 win 8434 (DF) 14:01:16.991795 wwwclient.blub.com.1853 > extern.bla.com.8000: S 584106440:584106440(0) win 8192 <mss 1460> (DF) 14:01:16.992505 extern.bla.com.8000 > wwwclient.blub.com.1853: S 105911:105911(0) ack 584106441 win 8760 <mss 1460> (DF) 14:01:17.052302 wwwclient.blub.com.1853 > extern.bla.com.8000: . ack 1 win 8760 (DF) 14:01:17.061141 wwwclient.blub.com.1853 > extern.bla.com.8000: P 1:327(326) ack 1 win 8760 (DF) 14:01:17.135638 extern.bla.com.8000 > wwwclient.blub.com.1853: P 1:207(206) ack 327 win 8434 (DF) 14:01:17.137412 extern.bla.com.8000 > wwwclient.blub.com.1853: . 207:1667(1460) ack 327 win 8434 (DF) 14:01:17.138615 extern.bla.com.8000 > wwwclient.blub.com.1853: . 1667:2921(1254) ack 327 win 8434 (DF) 14:01:17.157436 intern.bla.com > extern.bla.com: icmp: wwwclient.blub.com unreachable - need to frag (mtu 1462) 14:01:17.206994 wwwclient.blub.com.1853 > extern.bla.com.8000: . ack 207 win 8554 (DF) 14:01:17.209591 extern.bla.com.8000 > wwwclient.blub.com.1853: . 2921:4381(1460) ack 327 win 8434 (DF) 14:01:17.210204 extern.bla.com.8000 > wwwclient.blub.com.1853: . 4381:4587(206) ack 327 win 8434 (DF) 14:01:17.274191 wwwclient.blub.com.1853 > extern.bla.com.8000: . ack 207 win 8554 (DF) 14:01:19.820204 extern.bla.com.8000 > wwwclient.blub.com.1853: . 207:1667(1460) ack 327 win 8434 (DF) 14:01:19.839720 intern.bla.com > extern.bla.com: icmp: wwwclient.blub.com unreachable - need to frag (mtu 1462) 14:01:25.071207 extern.bla.com.8000 > wwwclient.blub.com.1853: . 207:1667(1460) ack 327 win 8434 (DF) 14:01:25.090643 intern.bla.com > extern.bla.com: icmp: wwwclient.blub.com unreachable - need to frag (mtu 1462) 14:01:35.573221 extern.bla.com.8000 > wwwclient.blub.com.1853: . 207:1667(1460) ack 327 win 8434 (DF) 14:01:35.592922 intern.bla.com > extern.bla.com: icmp: wwwclient.blub.com unreachable - need to frag (mtu 1462) 14:01:46.869095 wwwclient.blub.com.1853 > extern.bla.com.8000: F 327:327(0) ack 207 win 8554 (DF) 14:01:46.869722 extern.bla.com.8000 > wwwclient.blub.com.1853: . ack 328 win 8434 (DF) 14:01:49.466426 extern.bla.com.8000 > wwwclient.blub.com.1852: . 0:1460(1460) ack 1 win 8434 (DF) 14:01:49.485886 intern.bla.com > extern.bla.com: icmp: wwwclient.blub.com unreachable - need to frag (mtu 1462) Tcpdump on the internal interface: 14:01:16.991966 wwwclient.blub.com.1853 > wwwserver.intern.bla.com.8000: S 584106440:584106440(0) win 8192 <mss 1460> (DF) 14:01:16.992354 wwwserver.intern.bla.com.8000 > wwwclient.blub.com.1853: S 105911:105911(0) ack 584106441 win 8760 <mss 1460> (DF) 14:01:17.052445 wwwclient.blub.com.1853 > wwwserver.intern.bla.com.8000: . ack 1 win 8760 (DF) 14:01:17.061270 wwwclient.blub.com.1853 > wwwserver.intern.bla.com.8000: P 1:327(326) ack 1 win 8760 (DF) 14:01:17.135488 wwwserver.intern.bla.com.8000 > wwwclient.blub.com.1853: P 1:207(206) ack 327 win 8434 (DF) 14:01:17.137195 wwwserver.intern.bla.com.8000 > wwwclient.blub.com.1853: . 207:1667(1460) ack 327 win 8434 (DF) 14:01:17.138187 wwwserver.intern.bla.com.8000 > wwwclient.blub.com.1853: . 1667:2921(1254) ack 327 win 8434 (DF) 14:01:17.207135 wwwclient.blub.com.1853 > wwwserver.intern.bla.com.8000: . ack 207 win 8554 (DF) 14:01:17.209276 wwwserver.intern.bla.com.8000 > wwwclient.blub.com.1853: . 2921:4381(1460) ack 327 win 8434 (DF) 14:01:17.209397 wwwserver.intern.bla.com.8000 > wwwclient.blub.com.1853: . 4381:4587(206) ack 327 win 8434 (DF) 14:01:17.274311 wwwclient.blub.com.1853 > wwwserver.intern.bla.com.8000: . ack 207 win 8554 (DF) 14:01:19.819997 wwwserver.intern.bla.com.8000 > wwwclient.blub.com.1853: . 207:1667(1460) ack 327 win 8434 (DF) 14:01:25.070995 wwwserver.intern.bla.com.8000 > wwwclient.blub.com.1853: . 207:1667(1460) ack 327 win 8434 (DF) 14:01:35.572995 wwwserver.intern.bla.com.8000 > wwwclient.blub.com.1853: . 207:1667(1460) ack 327 win 8434 (DF) Dr. Ingmar Hartl, MIT, Rm 36-357, 77 Mass. Ave., Cambridge, MA 02139-4307 Phone: +1 (617) 253 8939, Fax: +1 (617) 253 9611, e-mail: [EMAIL PROTECTED] pgp fingerprint= E9 89 D3 8C D9 B5 AA 15 A1 A4 37 B3 A4 6E DF 8D key at http://wwwkeys.pgp.net:11371/pks/lookup?op=index&search=0x644D90A9 _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
