/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
chad wrote:
> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
>
>
> hello. i have a question regarding ipmasqadm.
>
> my questions are regarding ip forwarding in a mandrake (red hat) linux 6.1
> environment. from everything i have read, my kernel (2.2.9-19mdk) has
> forwarding built into it already. i am able to forward outgoing packets
> from our internal private network, so i will say that is another proof for
> it (maybe im wrong?).
>
>
> the implementation i am trying is to port forward packets from the external
> nic (internet) into our local network (intranet) via this mandrake linux
> firewall. i have used the following packages and rulesets with no luck.
> these have been added into my rc.local file so i may test. the machine has
> a different set of ipchains normally. i flushed all the rules so i may test
> ipchains/ipmasqadm w/o other rules getting into the way.
>
> ----packages----
> ipchains-1.3.8-4mdk.i586.rpm
> ipmasqadm-0.4.2-3.i386.rpm
>
> ----rulesets----
> ## Adding port forwarding via modprobe (not sure this is required but better
> safe than sorry?)
> /sbin/modprobe ip_masq_portfw.o
>
> ## Set up kernel to enable IP masquerading
> echo 1 > /proc/sys/net/ipv4/ip_forward
>
> ## Set up kernel to handle dynamic IP masquerading
> echo 1 > /proc/sys/net/ipv4/ip_dynaddr
>
> ## Set Default rule on MASQ chain to Deny
> $IPCHAINS -P forward DENY
>
> #FTPD
> $IPCHAINS -A input -p tcp -s 0/0 -d 208.235.151.91/32 21 -j ACCEPT
>
> ### Start Port Fowarding Services With ipmasqadm
> $IPCHAINS -I forward -p tcp -s 10.1.1.0/24 -j MASQ
>
> printf "\n\nstarting port forwarding services...\n\n"
> ipmasqadm portfw -f
> ipmasqadm portfw -a -P tcp -L 208.235.151.91 21 -R 10.1.1.2 21
> ipmasqadm portfw -l
> printf "\nport forwarding started.\n\n"
>
> when i said no luck above, i mean there is no connection. i have tested
> this from outside our internal network (my machine at home).
>
> i do not know of any other settings to add/change to make this configuration
> work. i believe all the settings are the same as what i have read on other
> ip masq howto sites/documents. any ideas here would be greatly appreciated.
ipchains is up to 1.3.9 so you might want to upgrade that.
i can't see why you're not getting an initial connection but
even if you did, you'd also have to allow the ftp data channel.
your firewall rules only allow the ftp command channel.
try loading the ip_masq_ftp module as well. it may solve your problem.
failing that, use log messages and tcpdump to trace what's going
on. that might help.
raf
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.