/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Hi! raf wrote: > > Hajime Lucky Okada wrote: > > > Still there is a little problem about ftp, so I will try to use the tool > > "fwhelper" you introduced me for it. > > you probably need to load the ip_masq_ftp module. > check that out first. Yes! ip_masq_ftp module is placed in directory of modules and included in the kernel from booting. About ftp, I could establish connection using PASV mode, without changing any rules. It's OK, no? So, I will show it to my amigos to use ftp in this mode. > > > also, it looks like the firewall/masquerading host will masquerade > > > any packets that it receives via eth1 that need to be forwarded via > > > eth2 or vice versa. this is probably a mistake. do something like > > > the following to prevent this: > > > > > > # Accept (unmasqueraded) traffic amongst multiple internal networks > > > > > > for src in $INTERNAL_NETWORKS > > > do > > > for dst in $INTERNAL_NETWORKS > > > do > > > if [ "$src" != "$dst" ] > > > then > > > ipchains -A forward -s $src -d $dst -j ACCEPT > > > fi > > > done > > > done > > > > > > # Masquerade traffic from internal networks to the outside world > > > > > > for masqnet in $INTERNAL_NETWORKS > > > do > > > ipchains -A forward -s $masqnet -j MASQ > > > done > > > > About this, I have to add explanation. > > > > To say exactly, I settle a data base host protected by firewall on the > > another network "eth1", that functions passively. > > > > On HOST-F/W, I have HOST-1 to be able to access to both of HOST-WWW > > thru eth0 and data base host thru eth1. > > The HOST-WWW and data base host only reply for this access from HOST-1, > > principally. When this access from HOST-1, the ip address would be > > masquerade to eth0 (to HOST-WWW) or to eth1 (to data base host). > > > > In this moment, the data base host will not access to another host > > by itself. > > > > In very near future, the HOST-WWW should access to the data base host > > to serve it's data on Web. For this, I will allow it by applying > > rules of port forwarding 'ipmasqadm' on HOST-F/W from eth0 to eth1, > > because the access should be very limited. > > > > So, I think it would not be so necessary for applying above scripts > > for this schematic, what dp you think? > > hard to say from here. i'd suggest not worrying about it unless > it turns out to be a problem. it's just that all packets travelling > via HOST-F/W via eth1 to the database host will be masqueraded to > look like they came from HOST-F/W even when they originated on HOST-1. > of course, this might not be a problem at all. just wait and see :) Ya, my strategy is just you said! >From HOST-1 on internal network, all packet can pass to both HOST-WWW and HOST-DB, masquerading it's packet that looks like from HOST-F/W. In this moment, this has functions correctly, I think. Now, would you give me one more suggestion? I show more simple schematic again. Internet | Router | +---[HOST-WWW] | (eth0) ---+---------(eth2) HOST F/W (eth1)------+--- | | [HOST-1] [HOST-DB] Here, HOST-1 can access freely to HOST-DB and HOST-WWW, also internet. The question is if I can add one more masquerading rule from HOST-DB to HOST-WWW. HOST-WWW has a global DNS for maintaining our zone to internet, but the hostname would be "masqueraded" to internet. I want to settle one more DNS for private use that can solve ONLY private hosts exactly and only forward to DNS on HOST-WWW to solve hosts on internet. So, I want to allow the packets of TCP/UDP (to port 53) access only to HOST-WWW from HOST-DB, by this new masquerading rule. The access from HOST-WWW to HOST-DB, I will allow only it by port forwarding of ipmasqadm. (Is there no problem, too?) Fundamentally, from internet (HOST-WWW) cannot access to inside of HOST-F/W, even if ping, except very limited DB access, theoretically... I hope so. Now, that's all. > > PS: Is there no way to receive these message in each... > > (not digest version) ??? > > yes, there is. go to http://www.indyramp.com/mailman/listinfo/masq > from there you can enter your mail address at the bottom and click > "Edit Options" which takes you a page where you can turn off digest > mode. Is the direction http://home.indyramp.com/mailman/listinfo/masq ? I try. So, thanx again, especially to raf (^*^)// Jaime. PS: Here only in English? No se puede escribir en espaqol? Por supuesto, no? -- Hajime Lucky Okada Email) [EMAIL PROTECTED] <HOME> http://www2.osk.3web.ne.jp/~luckyo/ _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.

Reply via email to