/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! /* ALSO: Don't quote this header. It makes you look lame :-) */ Hey Everyone, Sorry things have been so quiet around here but I've been pretty busy but I didn't stop working on TrinityOS and the IPMASQ howto. I just haven't been publishing it nearly as often as I should. For now, I have posted the new IP Masq HOWTO v1.90 with some serious updates to both my WWW page and the LDP: http://www.ecst.csuchico.edu/~dranch/LINUX/index-linux.html#ipmasq ALSO: Hopefully if I can test the new rule set in the next day or so, I will be posting a substantially enhanced, mostly spell checked, and CLEANED UP TrinityOS! If anything else, the new rc.firewall ruleset has been greatly enhanced! Until then, here is the IP Masq ChangeLOG: PS. 472 people on the Updates list! Please keep telling your friends, user groups, etc. The more people submit ideas, help, etc, the better I can make the docs! --David -- Changes from 1.85 to 1.90 - 07/03/00 * Updated the URL for TrinityOS to reflect its new layout * Caught a typo in the IPCHAINS rulesets where I was setting "ip_ip_always_defrag" instead of "ip_always_defrag" * The URL to Taro Fukunaga was invaild since it was using "mail:" instead of "mailto:" * Added some clarification to the "Masqing multiple internal interfaces" where some people didn't understand why eth0 was referenced multiple times. * Fixed another "space after the EXTIP variable" bug in the stronger IPCHAINS section. I guess I missed one. * In Test #7 of Section 5, I referred users to go back to step #4. Thats should have been step #6. *Updated the kernel versions that came with SuSe 5.2 and 6.0 * Fixed a typo (or vs. of) in Section 7.2 * Added Item #9 to the Testing MASQ section to refer users who are still haing MASQ problems to read the MTU entry in the FAQ * Improved the itemization in Section 5 * Updated the IPCHAINS syntax to show the MASQ/FORWARD table. Before, it was valid to run "ipchains -F -L" but now only "ipchains -M -L" works. * Updated the LooseUDP documentation to reflect the new LooseUDP behavior in 2.2.16+ kernels. Before, it was always enabled, now, it defaults to OFF due to a possible MASQed UDP port scanning vunerability. I have updated the BASIC and SEMI-STRONG IPCHAINS rulesets to reflect this option. * Updated the recommended 2.2.x kernel to be 2.2.16+ since there is a TCP root exploit vunerability in all lesser versions. * Added Redhat 6.2 to the MASQ supported list * Updated the link for Sonny Parlin's FWCONFIG to now point to fBuilder. * Updated the various example IP addresses from 111.222.333.444 to be 111.222.121.212 to be within a valid IP address range * Updated the URL for the BETA H.323 MASQ module * Finally updated the MTU FAQ section to help out PPPoE DSL and Cablemodem users. * Basically, the MTU-issues section now reflects that users can also change the MTU settings of all of their INTERNAL machines to solve the dreaded MASQ MTU issue. * Added a clarification to the PORTFW section that PORTFWed connections that work for EXTERNAL clients will not work for INTERNAL clients. If you also need INTERNAL portfw, you will need to also impliment the REDIR tool as well. I also noted that this issue is fixed in the 2.4.x kernels with Netfilter. * I also added a technical explination from Juanjo to the end of the PORTFW section to why this senario doesn't work properly. * Updated all of the IPCHAINS URLs to point to Paul Rusty's new site at http://netfilter.filewatcher.org/ipchains/ * Updated Paul Rustys email address * Added a new FAQ section for users whose connections remain idle for a long time and their PORTFWed connection no longer work. * Updated all the URLs to the LDP that pointed to metalab.unc.edu to the new site of linuxdoc.org * Updated the Netfilter URLs to point to renamed HOWTOs, etc. * I also updated the status of the 2.4.x support to note that I *will* add full Netfilter support to this HOWTO and if the time comes, then split that support off into a different HOWTO. * Updated the 2.4.x Requirements section to reflect how NetFilter has changed compared to IPFWADM and IPCHAINS and gave a PROs/CONs list of new features and changes to old behaviors. * Added a TCP/IP math example to the "My MASQ connection is slow" FAQ entry to better explain what a user should expect performance wise. * Updated the HOWTO to reflect that newer versions of the "pump" DHCP client now can run scripts upon bringup, lease renew, etc. * Updated the PORTFWing of FTP to reflect that several users say they can successfully forward FTP traffic to internal machines without the need of a special ip_masq_ftp module. I have made the HOWTO reflect that users should try it without the modified module first and then move to the patch if required. -- .----------------------------------------------------------------------------. | David A. Ranch - Linux/Networking/PC hardware [EMAIL PROTECTED] | !---- ----! `----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----' _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
