Re: newbie iptables question

2004-08-14 Thread s. keeling
Incoming from Daniel Pittman: > On 14 Aug 2004, s. keeling wrote: > > > > Are you suggesting that I might see stuff in my logs that was destined > > for a foreign IP? > > Not often, but occasionally, depending on how your ISP connects you to > the Internet. It is most common on a LAN or a cable

Re: Static NAT w/ iptables problem

2004-08-14 Thread Philipp Schulte
Markus Trümper wrote: > Testing is done by connecting a dedicated computer to each interface and trying > to reach the one on the internal net from the DMZ. The firewall can reach each > computer and each computer can reach the firewall (ping). > > My rules so far don't work. I can not reach 'se

Re: Static NAT w/ iptables problem

2004-08-14 Thread Stephen Gran
This one time, at band camp, Markus Trümper said: > Hello, > > I'm trying to set up a firewall to do static NAT between two networks: > >internal network > 192.168.1.0/24 > >server 192.168.1.3 >| > LAN_IF 192.168.1.7 > Firewall > EXT_IF 10.80.137.1, 10.80.137.1

unsubscribe

2004-08-14 Thread mlreaders
-- || | || | || | || | || | || | || | || | || | || | || | || | || ||| | || hyperraum | webvisionen http://www.hyperraum.net/ / websolutions / information strategies / eLearning / Flash / Databases / 3D Graphics & VR || | || | || | || | || | || | || | || | || | || | || | || | || |||

Static NAT w/ iptables problem

2004-08-14 Thread Markus Trümper
Hello, I'm trying to set up a firewall to do static NAT between two networks: internal network 192.168.1.0/24 server 192.168.1.3 | LAN_IF 192.168.1.7 Firewall EXT_IF 10.80.137.1, 10.80.137.10 | DMZ 10.80.137.0/24 'server' should be reachable from

Re: newbie iptables question

2004-08-14 Thread Wanda Round
Phillip Hofmeister <[EMAIL PROTECTED]> wrote in message news:<[EMAIL PROTECTED]>... > It is saying a rule matched. Doesn't say what you did with the packet > though, just tells you about the packet. If you want to know what you > did with it you would need to include a log-prefix in your iptables

Re: newbie iptables question

2004-08-14 Thread Daniel Pittman
On 14 Aug 2004, s. keeling wrote: > Incoming from Bernd Eckenfels: >> In article <[EMAIL PROTECTED]> you wrote: >> Aug 12 04:36:53 towern kernel: |iptables -- IN=ppp0 OUT= MAC= >> SRC=201.129.122.85 DST=12.65.24.43 LEN=48 TOS=0x00 PREC=0x00 TTL=115 >> ID=40023 DF PROTO=TCP SPT=4346 DPT

Re: newbie iptables question

2004-08-14 Thread Bernd Eckenfels
In article <[EMAIL PROTECTED]> you wrote: >> Well, you need to check if DST= is a local address, anyway. > > Are you suggesting that I might see stuff in my logs that was destined > for a foreign IP? If so, that would make me an open mail relay, no? If your system is a gateway, this is quite com