/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


I'm currently having a problem with masquerading UDP packets back and forth
thru my linux box.

I have a Redhat linux 6.0 system (kernel 2.2.5-15), I have to use this
release/kernel because
that's what the drivers I have for my network gear support (they are
binaries, rather the source).

I have an ABA2030 Satelite Reciever card (made by BoardLogic, also called
the "Satelite Express+".
All incoming traffic from my static IP comes in through this interface
(aba_0) and all traffic
goes out via my dial up circuit (ppp0).  Everything seems to work fine with
very few ipchaining
rules (here's my rules at the moment).

ipchains -M -S 7200 10 160
ipchains -P forward DENY
ipchains -A forward -s 192.168.1.0/255.255.255.0 -j MASQ
ipchains -A input -s 207.46.204.0/24 -d 0/0 9000:9013 -p 17 -j ACCEPT

my local network is 192.168.1.* and the linux machines local IP is
192.168.1.1

The problem for me is hard to "define".  TCP seems to work just fine, and
outgoing UDP traffic
also works fine.  The problem is when UDP traffic comes back I don't think
all of it is being
forwarded back to the request machine on the network.

In particular my friends like to play the game "Asherons Call" through the
gateway, if I dialup
with just the modem and avoid using the satelite return (By using a
different dialup account)
this game will operate fine.  This game uses UDP, ports 9000 thru 9013 for
IP addresses 207.46.204.*
to send back UDP packets, here is exactly what it does:

Connection AC IP address Port(s)

Initial UDP Outbound 207.46.204.*               9000
Subsequent UDP Outbound 207.46.204.*    9004, 9008, 9012
Subsequent UDP Inbound 207.46.204.*     9000, 9001, 9004, 9005, 9008, 9009,
9012, 9013

and

Connection AC IP address Port(s)
Initial UDP Outbound 207.46.204.*               9004
Subsequent UDP Outbound 207.46.204.*    9000, 9008, 9012
Subsequent UDP Inbound 207.46.204.*     9000, 9001, 9004, 9005, 9008, 9009,
9012, 9013

Now when he trys to play the game while using the satelite return-path it
will get have way though
connecting, gets into the game and then fails to recieve some of the
information.

My guess (however I'm not at all certain) is that the subsequent UDP inbound
ports 9001,9005,9009,90013
and maybe others aren't geting fed back properly (though how masquerading
deals with UDP packets is
still a bit of a mystery to me - could anyone point me to a good resouce for
information on this, how
does the masquerading box know how to funnel packets back to the original
machine, when know connection
is established..

Any help would be greatly recieved, if someone feels they have information
not necessarily usefull to
the mailing list just email me directly:  [EMAIL PROTECTED]

Thanks,

 - Alex

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to