/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Hajime Lucky Okada wrote:
> Hi!
>
> raf wrote:
> >
> > Hajime Lucky Okada wrote:
> >
> > > Still there is a little problem about ftp, so I will try to use the tool
> > > "fwhelper" you introduced me for it.
> >
> > you probably need to load the ip_masq_ftp module.
> > check that out first.
>
> Yes! ip_masq_ftp module is placed in directory of modules and
> included in the kernel from booting.
>
> About ftp, I could establish connection using PASV mode, without
> changing any rules. It's OK, no?
> So, I will show it to my amigos to use ftp in this mode.
yes. that's ok. with passive mode, all connections are initiated
by the client, inside the firewall, which is good. with normal/active
mode, the ftp server, outside the firewall, initiates the connection
for the data channel which is bad. only use passive mode ftp.
> > > > also, it looks like the firewall/masquerading host will masquerade
> > > > any packets that it receives via eth1 that need to be forwarded via
> > > > eth2 or vice versa. this is probably a mistake. do something like
> > > > the following to prevent this:
> > > >
> > > > # Accept (unmasqueraded) traffic amongst multiple internal networks
> > > >
> > > > for src in $INTERNAL_NETWORKS
> > > > do
> > > > for dst in $INTERNAL_NETWORKS
> > > > do
> > > > if [ "$src" != "$dst" ]
> > > > then
> > > > ipchains -A forward -s $src -d $dst -j ACCEPT
> > > > fi
> > > > done
> > > > done
> > > >
> > > > # Masquerade traffic from internal networks to the outside world
> > > >
> > > > for masqnet in $INTERNAL_NETWORKS
> > > > do
> > > > ipchains -A forward -s $masqnet -j MASQ
> > > > done
> > >
> > > About this, I have to add explanation.
> > >
> > > To say exactly, I settle a data base host protected by firewall on the
> > > another network "eth1", that functions passively.
> > >
> > > On HOST-F/W, I have HOST-1 to be able to access to both of HOST-WWW
> > > thru eth0 and data base host thru eth1.
> > > The HOST-WWW and data base host only reply for this access from HOST-1,
> > > principally. When this access from HOST-1, the ip address would be
> > > masquerade to eth0 (to HOST-WWW) or to eth1 (to data base host).
> > >
> > > In this moment, the data base host will not access to another host
> > > by itself.
> > >
> > > In very near future, the HOST-WWW should access to the data base host
> > > to serve it's data on Web. For this, I will allow it by applying
> > > rules of port forwarding 'ipmasqadm' on HOST-F/W from eth0 to eth1,
> > > because the access should be very limited.
> > >
> > > So, I think it would not be so necessary for applying above scripts
> > > for this schematic, what dp you think?
> >
> > hard to say from here. i'd suggest not worrying about it unless
> > it turns out to be a problem. it's just that all packets travelling
> > via HOST-F/W via eth1 to the database host will be masqueraded to
> > look like they came from HOST-F/W even when they originated on HOST-1.
> > of course, this might not be a problem at all. just wait and see :)
>
> Ya, my strategy is just you said!
>
> >From HOST-1 on internal network, all packet can pass to both
> HOST-WWW and HOST-DB, masquerading it's packet that looks like
> from HOST-F/W. In this moment, this has functions correctly, I
> think.
>
> Now, would you give me one more suggestion?
> I show more simple schematic again.
>
> Internet
> |
> Router
> |
> +---[HOST-WWW]
> |
> (eth0)
> ---+---------(eth2) HOST F/W (eth1)------+---
> | |
> [HOST-1] [HOST-DB]
>
> Here, HOST-1 can access freely to HOST-DB and HOST-WWW, also
> internet.
> The question is if I can add one more masquerading rule from
> HOST-DB to HOST-WWW.
>
> HOST-WWW has a global DNS for maintaining our zone to internet,
> but the hostname would be "masqueraded" to internet.
> I want to settle one more DNS for private use that can solve ONLY
> private hosts exactly and only forward to DNS on HOST-WWW to solve hosts
> on internet.
>
> So, I want to allow the packets of TCP/UDP (to port 53) access
> only to HOST-WWW from HOST-DB, by this new masquerading rule.
>
> The access from HOST-WWW to HOST-DB, I will allow only it by port
> forwarding of ipmasqadm. (Is there no problem, too?)
sounds good. of course, there's only one way to tell :)
> Fundamentally, from internet (HOST-WWW) cannot access to inside of HOST-F/W,
> even if ping, except very limited DB access, theoretically... I hope so.
>
> Now, that's all.
>
> > > PS: Is there no way to receive these message in each...
> > > (not digest version) ???
> >
> > yes, there is. go to http://www.indyramp.com/mailman/listinfo/masq
> > from there you can enter your mail address at the bottom and click
> > "Edit Options" which takes you a page where you can turn off digest
> > mode.
>
> Is the direction http://home.indyramp.com/mailman/listinfo/masq ?
yes
> I try.
>
> So, thanx again, especially to raf (^*^)//
> Jaime.
da nada
> PS: Here only in English?
> No se puede escribir en espaqol? Por supuesto, no?
es posible pero mi espaqol es muy poco.
inglis es mucho mas facil para mm.
> --
> Hajime Lucky Okada
>
> Email) [EMAIL PROTECTED]
raf
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.