/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Hajime Lucky Okada wrote:

> I'm just setting up firewall in our system shown in following figure 
> using ipchains.
> 
> I want to establish transparently connection from HOST-1 to HOST-WWW 
> and internet. That is, from HOST-1 located in internal network to outer 
> of firewall can be accessed freely, but opposed direction should be 
> limited restrictedly at the firewall host.
> 
> I tried to define rules shown bellow for this. 
> BUT, in this process I have big problem as follows. I'm very confused why..
> Please give me any suggestions!!
> 
> 
> [Problem]
> The ping from HOST-1 to HOST-WWW does not return to HOST-1.
> 
> [Situation]
> 1. Without setting firewall, ping and another protocol like ftp can be
>    established between HOST-1 and HOST-WWW.
>    This means that the basic configuration of network, like 
>    managing hardware, IP/MASK address and gateway, should be proper, 
>    I think.
> 
> 2. But, once I have set the rules of ipchains, the packet of ping 
>    is blocked...
>    From a message of $(/sbin/ipchains -L -v), the packet of ping could 
>    pass eth0 of HOST-1, eth2 of HOST-F/W, ip address masquerading, eth0 
>    of HOST-F/W and could reach to HOST-WWW.  HOST-WWW replied ping to 
>    HOST-F/W because the source address has been masqueraded. 
>    The replied ping packet is accepted to eth0 of HOST-F/W.
> 
> 3. Nextly the problem occurs.  
>    I don't why, but the output from eth2 of HOST-F/W to eth0 of HOST-1 
>    seems to be blocked by "DENY POLICY" rule... by the message of ipchians.
>    As result, the connection of ping is failed.
> 
> So... what wrong thing do I do???

make sure that you have configured the kernel to masquerade icmp packets
since it doesn't by default (the option is called something like
MASQUERADE_ICMP).

if that's not the problem, go to
http://www.zip.com.au/~raf2/lib/software/firewall
there's a utility in there called fwhelper which
simulates the packet matching algorithm and shows
a trace so you can see what rules match or not and
why or why not. it's like "ipchains -C" but useful.

> Another thing, how can I do logging packets rejected by "DENY POLICY"?

make the last rule on the chain do nothing but log.
e.g.
  ipchains -A input -l
  ipchains -A output -l

also, it looks like the firewall/masquerading host will masquerade
any packets that it receives via eth1 that need to be forwarded via
eth2 or vice versa. this is probably a mistake. do something like
the following to prevent this:

    # Accept (unmasqueraded) traffic amongst multiple internal networks

    for src in $INTERNAL_NETWORKS
    do
        for dst in $INTERNAL_NETWORKS
        do
            if [ "$src" != "$dst" ]
            then
                ipchains -A forward -s $src -d $dst -j ACCEPT
            fi
        done
    done

    # Masquerade traffic from internal networks to the outside world

    for masqnet in $INTERNAL_NETWORKS
    do
        ipchains -A forward -s $masqnet -j MASQ
    done

raf

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to