On 20 May 99, at 12:36, Stephen Mills wrote about
"Re: [Masq] exception to the rule":
| Hi Mich,
|
| No I havent tried that, I can't see why that wouldn't work, but Im not all
| that keen on recompiling the kernel because its at a customers site.
| Actually there is a port forwarder that can forward without hacking the
| kernel, only supports TCP which would work...hmmm, there must be a way with
| ipfwadm ?
Port forwarding? As a technique to deny traffic? I must be dense, I
don't get it. ipfwadm filtering should be the right answer.
You weren't too specific about what you tried that didn't work. If
it was a Forward or Output rule, it won't work because masquerading
has already taken place. It should be a pair of Input rules on the
local interface: the first accepting traffic from the restricted IP
to the local net, and the second denying all other packets from the
restricted IP.
Is that what you tried?
| --Stephen
|
| ----- Original Message -----
| From: Mich <[EMAIL PROTECTED]>
| To: Stephen Mills <[EMAIL PROTECTED]>
| Sent: Thursday, May 20, 1999 9:41 AM
| Subject: Re: [Masq] exception to the rule
|
|
| > Stephen,
| >
| > have you tried to just port forward that connection to another port it may
| > be a work around
| >
| > Mich
| >
| > ----- Original Message -----
| > From: Stephen Mills <[EMAIL PROTECTED]>
| > To: <[EMAIL PROTECTED]>
| > Sent: Wednesday, May 19, 1999 7:13 PM
| > Subject: [Masq] exception to the rule
|...
| > > Simply, I would like one workstation *not* to be able to browse the web,
| > and
| > > the rest of the Class A network to be able to.
Do you want the restricted machine to have *no* external access, or
just restrict HTTP? For just HTTP, you'd want to add
"-D 0.0.0.0/0 80" to the deny rule.
| > > If I put the deny rule stating that this IP address isnt allowed the
| > browse
| > > etc, and the rest of the Class A is, rule one gets ignored, and all
| > > workstations are allowed to browse.
What rule, specifically?
HTH...
- Fred Viles <mailto:[EMAIL PROTECTED]>
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]