/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Hajime Lucky Okada wrote:
> I'm just setting up firewall in our system shown in following figure
> using ipchains.
>
> I want to establish transparently connection from HOST-1 to HOST-WWW
> and internet. That is, from HOST-1 located in internal network to outer
> of firewall can be accessed freely, but opposed direction should be
> limited restrictedly at the firewall host.
>
> I tried to define rules shown bellow for this.
> BUT, in this process I have big problem as follows. I'm very confused why..
> Please give me any suggestions!!
>
>
> [Problem]
> The ping from HOST-1 to HOST-WWW does not return to HOST-1.
>
> [Situation]
> 1. Without setting firewall, ping and another protocol like ftp can be
> established between HOST-1 and HOST-WWW.
> This means that the basic configuration of network, like
> managing hardware, IP/MASK address and gateway, should be proper,
> I think.
>
> 2. But, once I have set the rules of ipchains, the packet of ping
> is blocked...
> From a message of $(/sbin/ipchains -L -v), the packet of ping could
> pass eth0 of HOST-1, eth2 of HOST-F/W, ip address masquerading, eth0
> of HOST-F/W and could reach to HOST-WWW. HOST-WWW replied ping to
> HOST-F/W because the source address has been masqueraded.
> The replied ping packet is accepted to eth0 of HOST-F/W.
>
> 3. Nextly the problem occurs.
> I don't why, but the output from eth2 of HOST-F/W to eth0 of HOST-1
> seems to be blocked by "DENY POLICY" rule... by the message of ipchians.
> As result, the connection of ping is failed.
>
> So... what wrong thing do I do???
make sure that you have configured the kernel to masquerade icmp packets
since it doesn't by default (the option is called something like
MASQUERADE_ICMP).
if that's not the problem, go to
http://www.zip.com.au/~raf2/lib/software/firewall
there's a utility in there called fwhelper which
simulates the packet matching algorithm and shows
a trace so you can see what rules match or not and
why or why not. it's like "ipchains -C" but useful.
> Another thing, how can I do logging packets rejected by "DENY POLICY"?
make the last rule on the chain do nothing but log.
e.g.
ipchains -A input -l
ipchains -A output -l
also, it looks like the firewall/masquerading host will masquerade
any packets that it receives via eth1 that need to be forwarded via
eth2 or vice versa. this is probably a mistake. do something like
the following to prevent this:
# Accept (unmasqueraded) traffic amongst multiple internal networks
for src in $INTERNAL_NETWORKS
do
for dst in $INTERNAL_NETWORKS
do
if [ "$src" != "$dst" ]
then
ipchains -A forward -s $src -d $dst -j ACCEPT
fi
done
done
# Masquerade traffic from internal networks to the outside world
for masqnet in $INTERNAL_NETWORKS
do
ipchains -A forward -s $masqnet -j MASQ
done
raf
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.