/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Hi!
raf wrote:
>
> Hajime Lucky Okada wrote:
>
> > Still there is a little problem about ftp, so I will try to use the tool
> > "fwhelper" you introduced me for it.
>
> you probably need to load the ip_masq_ftp module.
> check that out first.
Yes! ip_masq_ftp module is placed in directory of modules and
included in the kernel from booting.
About ftp, I could establish connection using PASV mode, without
changing any rules. It's OK, no?
So, I will show it to my amigos to use ftp in this mode.
> > > also, it looks like the firewall/masquerading host will masquerade
> > > any packets that it receives via eth1 that need to be forwarded via
> > > eth2 or vice versa. this is probably a mistake. do something like
> > > the following to prevent this:
> > >
> > > # Accept (unmasqueraded) traffic amongst multiple internal networks
> > >
> > > for src in $INTERNAL_NETWORKS
> > > do
> > > for dst in $INTERNAL_NETWORKS
> > > do
> > > if [ "$src" != "$dst" ]
> > > then
> > > ipchains -A forward -s $src -d $dst -j ACCEPT
> > > fi
> > > done
> > > done
> > >
> > > # Masquerade traffic from internal networks to the outside world
> > >
> > > for masqnet in $INTERNAL_NETWORKS
> > > do
> > > ipchains -A forward -s $masqnet -j MASQ
> > > done
> >
> > About this, I have to add explanation.
> >
> > To say exactly, I settle a data base host protected by firewall on the
> > another network "eth1", that functions passively.
> >
> > On HOST-F/W, I have HOST-1 to be able to access to both of HOST-WWW
> > thru eth0 and data base host thru eth1.
> > The HOST-WWW and data base host only reply for this access from HOST-1,
> > principally. When this access from HOST-1, the ip address would be
> > masquerade to eth0 (to HOST-WWW) or to eth1 (to data base host).
> >
> > In this moment, the data base host will not access to another host
> > by itself.
> >
> > In very near future, the HOST-WWW should access to the data base host
> > to serve it's data on Web. For this, I will allow it by applying
> > rules of port forwarding 'ipmasqadm' on HOST-F/W from eth0 to eth1,
> > because the access should be very limited.
> >
> > So, I think it would not be so necessary for applying above scripts
> > for this schematic, what dp you think?
>
> hard to say from here. i'd suggest not worrying about it unless
> it turns out to be a problem. it's just that all packets travelling
> via HOST-F/W via eth1 to the database host will be masqueraded to
> look like they came from HOST-F/W even when they originated on HOST-1.
> of course, this might not be a problem at all. just wait and see :)
Ya, my strategy is just you said!
>From HOST-1 on internal network, all packet can pass to both
HOST-WWW and HOST-DB, masquerading it's packet that looks like
from HOST-F/W. In this moment, this has functions correctly, I
think.
Now, would you give me one more suggestion?
I show more simple schematic again.
Internet
|
Router
|
+---[HOST-WWW]
|
(eth0)
---+---------(eth2) HOST F/W (eth1)------+---
| |
[HOST-1] [HOST-DB]
Here, HOST-1 can access freely to HOST-DB and HOST-WWW, also
internet.
The question is if I can add one more masquerading rule from
HOST-DB to HOST-WWW.
HOST-WWW has a global DNS for maintaining our zone to internet,
but the hostname would be "masqueraded" to internet.
I want to settle one more DNS for private use that can solve ONLY
private hosts exactly and only forward to DNS on HOST-WWW to solve hosts
on internet.
So, I want to allow the packets of TCP/UDP (to port 53) access
only to HOST-WWW from HOST-DB, by this new masquerading rule.
The access from HOST-WWW to HOST-DB, I will allow only it by port
forwarding of ipmasqadm. (Is there no problem, too?)
Fundamentally, from internet (HOST-WWW) cannot access to inside of HOST-F/W,
even if ping, except very limited DB access, theoretically... I hope so.
Now, that's all.
> > PS: Is there no way to receive these message in each...
> > (not digest version) ???
>
> yes, there is. go to http://www.indyramp.com/mailman/listinfo/masq
> from there you can enter your mail address at the bottom and click
> "Edit Options" which takes you a page where you can turn off digest
> mode.
Is the direction http://home.indyramp.com/mailman/listinfo/masq ?
I try.
So, thanx again, especially to raf (^*^)//
Jaime.
PS: Here only in English?
No se puede escribir en espaqol? Por supuesto, no?
--
Hajime Lucky Okada
Email) [EMAIL PROTECTED]
<HOME>
http://www2.osk.3web.ne.jp/~luckyo/
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.
- [Masq] ping does not return.... Hajime Lucky Okada
- Re: [Masq] ping does not return.... raf
- Re: [Masq] ping does not return.... Hajime Lucky Okada
- Re: [Masq] ping does not return.... raf
- Re: [Masq] ping does not return.... Hajime Lucky Okada
