/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Sorry, this will give you more of a picture of the mess I have...
Unfortuantely there are 2 firewalls to get through.

Here is the PC layout for you. I have 2 Linux boxes as "firwall 2" sometimes
connects to other ISPs instead of work.
Those firewall rules mentioned previously are running on Firewall 2 and I
try to connect FROM Windows machine at work to the IP of my firewall 2
machine on 10.10.10.68 which I assume would redirect to the home pc ports?
Correct? Or is that not how it's suppose to work?

Big mess ey?? Actually it's worse but this is the route it takes.....
WIndo$e  (work)        Linux firewall         Linux firwall 2
Windo$e (Home)

---------------    -----------------------    -----------------------------
---------------
| 10.10.0.69  +----+10.10.0.1 10.10.10.10+----+ 10.10.10.68 192.168.1.254
+--+ 192.168.1.1 |
---------------    | eth0           ppp0 |    | ppp0                eth0  |
---------------  
                   -----------------------    -----------------------------
PS: Hope you like my art work... hee hee ;-)


thanks,
George Vieira
Network Administrator
Citadel Computer Systems P/L
http://www.citadelcomputer.com.au



-----Original Message-----
From: Gregory Leblanc [mailto:[EMAIL PROTECTED]]
Sent: Wednesday, 17 May 2000 3:11 PM
To: 'George Vieira'; '[EMAIL PROTECTED]'
Subject: RE: [Masq] IPMASQADM PORTFW problem in redhat 6.1


> -----Original Message-----
> From: George Vieira [mailto:[EMAIL PROTECTED]]
> Sent: Tuesday, May 16, 2000 10:00 PM
> To: '[EMAIL PROTECTED]'
> Subject: [Masq] IPMASQADM PORTFW problem in redhat 6.1
> 
> /* HINT: Search archives @ http://www.indyramp.com/masq/ 
> before posting! */
> 
> I'm sorry if this isn't the right list or has been mentioned 
> a thousand
> times before but I need help with this redirection function 
> under RedHat 6.1
> 
> I have enabled IPforwarding and autoforwarding in the kernal 
> and have done
> an insmod for ip_forward and ip_masq_portfw.
> I have entered the following in a startup script to enable 
> forwarding..
> 
> # CLEAR any existing chains
> echo 1 > /proc/sys/net/ipv4/ip_forward
> echo 1 > /proc/sys/net/ipv4/ip_always_defrag
> echo 1 > /proc/sys/net/ipv4/ip_dynaddr
> echo 1 > /proc/sys/net/ipv4/tcp_syncookies
> echo 1 > /proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
> echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
> 
> /sbin/ipchains -F input
> /sbin/ipchains -F output
> /sbin/ipchains -F forward
> 
> /sbin/ipchains -M -S 7200 10 160
> 
> # DENY any attempts of SPOOFING
> /sbin/ipchains -A input -j DENY -i eth0 -s 192.168.1.0/24 -d 
> 0.0.0.0/0 -l
> 
> # FORWARD all local network to anywhere required.
> /sbin/ipchains -A forward -s 192.168.1.0/24 -d 0.0.0.0/0 -j MASQ
> 
> /usr/sbin/ipmasqadm portfw -a -P tcp -L 10.10.10.68 43188 -R 
> 192.168.1.1
> 43188
> 
> My main concern is that I still cannot access the internal machine on
> 192.168.1.1 to port 43188. It doesn't conmect or anything..
> 
> My question is "Is there anything majorly important that I 
> have missed or
> not mentioned"?

Yep, there always is.  :-)  How are you testing?  Unless you've patched the
kernel, then testing this from INSIDE the masq computer will NOT work.  You
MUST test from a machine outside of the MASQ router.  The syntax all looks
good there, so I'd suspect that it's probably working, you just can't test
that it is working.  :-/  Try again from an outside machine, or even email
me and I can give you a hand testing that if you don't have an external
machine to test from.
        Greg

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to