Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: linux: ipfw; ip-masq; eth0 and ppp0
From: "R. DuFresne" <dufresne @ darkstar . sysinfo . com>
Organization: Minn. Information Systems
Date: Tue, 15 Jul 1997 00:00:57 -0500 (CDT)
Newsgroups: comp.os.linux.misc, alt.os.linux.slackware, linux.sys.alpha

E-mail replies are requested and appreciated...

 So, what do you know about linux, ipfw, IP masquerade, and routing?
 
 I have the linux machine here, outsidehost.my.domain.com on
 XXX.XXX.XXX.XX ppp0, with a 3com 509b card <called
 insidehost.my.domain.com 192.168.80.1 eth0. The inside net has win 3.11
 and win95 machines, 192.168.80.XX, they are set with 192.168.80.1
 <insidehost> as their gateway.  I can watch all the packets on
 192.168.80.0/255 with various net tools, inculding tcpdump.  the win
 machines can play together fine in both tcp/ip and netbio.  But,
 insidehost will not recognize their packets and forward them on via
 outsidehost, and they seem to not see those of insidehost <e.g. arp
 replies>  So, they're at this point is nothing getting masqueraded out.
 All policies for ipfw are accept, to make it as open as possible now.
 Here's the route table on blackhole, have tried others:
 
 Kernel routing table
 Destination     Gateway         Genmask         Flags MSS    Window Use
 Iface
 gw.outside.net  *               255.255.255.255 UH    1500   0        3
 ppp0
 mydomain.com    *               255.255.255.0   U     1500   0       70
 eth0
 loopback        *               255.0.0.0       U     3584   0       95 lo
 default         gw.outside.net  *               UG    1500   0      604
 ppp0
 

 Linux outsidehost 2.0.23 #3 Fri Jun 6 20:52:07 CDT 1997 i586
 
 
 any clues?
 
 Thanks, my best to you and yours,
 
 Ron DuFresne
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
	admin & senior consultant:  darkstar.sysinfo.com
		  http://darkstar.sysinfo.com
"Cutting the space budget really restores my faith in humanity.  It
eliminates dreams, goals, and ideals and lets us get straight to the
business of hate, debauchery, and self-annihilation." -- Johnny Hart
	***testing, only testing, and damn good at it too!***

OK, so you're a Ph.D.  Just don't touch anything.


Indexed By Date Previous: Re: What is NAT?
From: "Jet B. Bagadion" <jbb @ solidbank . com . ph>
Next: Re: Hacking Attempt (fwd)
From: Michael Brennen <mbrennen @ fni . com>
Indexed By Thread Previous: linux firewalls
From: "Marites D. Constantino" <tex @ skyinet . net>
Next: [no subject]
From: Claudia Moroni <moroni @ irbm . it>

Google
 
Search Internet Search www.greatcircle.com