I am running the standard redhat 5.2 (linux 2.036).
behind the firewall I have only a win98.  Recently I have added a cisco 770
with an ISDN link to my office ( a few win 95, one MAC and one win NT).

Here is the map:
linux external:  to cable modem
linux internal:   10.0.0.221
Win 98:     10.0.0.223
cisco 770 :  10.0.0.254   routing on demand 10.10.10.0/24 to 10.10.10.254

at the office:
a subnet of 10.10.10.0/24 with a
cisco 760   IP 10.10.10.254 routing on demand 0.0.0.0/0 to 10.0.0.254

The problem is:
When I ping 10.10.10.x from my WIN98 computer, the ping goes through the
linux firewall instead of being routed by the cisco.  What is even more
puzzling is that the ping is successful !!!!
So, with a TCPDUMP, I have monitored my eth0 and discovered that many
10.x.x.x ip addresses respond to the ping.

Question:
1) do I have a hole in my firewall?   I enclose my rc.firewall script.  I
thought I was allowing only 10.0.0.0/24 out
2) Why do I get so many successful pings when I try 10.x.x.x?  (10.0.1.1,
10.0.8.1, 10.10.10.1, etc.)
3) And at last, as you read my rc.firewall, you will notice some
comments/questions that I have asked myself as I was implementing it.
Perhaps you can spread some light on those too.

Thanks so much.

========   my rc.firewall ======
#!/bin/sh
#
# Author Emil LAURENTIU
# Modified Sorin & Paolo Dec 1998
# Last Modified 13 Jul 1998
#
/sbin/modprobe ip_masq_ftp
#/sbin/modprobe ip_masq_raudio
#/sbin/modprobe ip_masq_irc
# /sbin/modprobe ip_masq_cuseeme
# /sbin/modprobe ip_masq_vdolive
IPADDR=`/sbin/ifconfig eth0 | /bin/awk '{
    if( $0 ~ /inet addr:/ ) { match($0,/[0-9]*\.[0-9]*\.[0-9]*\.[0-9]*/);
    print substr($0, RSTART, RLENGTH); }}'`
# Incoming, flush and set default policy to accept.
# -------------------------------------------------
/sbin/ipfwadm -I -f
# default policy accept
/sbin/ipfwadm -I -p accept
#
## local network
/sbin/ipfwadm -I -a accept -S 10.0.0.0/24 -D 0/0 -W eth1

######     Is the following a good idea   ????

# let only ping_reply and host unreachable from outside to pass
###/sbin/ipfwadm -I -P icmp -a accept -S 0/0 0 3 11 -W eth0
/sbin/ipfwadm -I -P icmp -a accept -S 0/0        -W eth0
# and deny all the remaining ICPM requests
###/sbin/ipfwadm -I -P icmp -a deny -W eth0 -o

##### and what the following.... Should I restrict????

# warning: the following line, instead of the one below, opens everything,
but ineed it to test netcom
/sbin/ipfwadm -I -a accept -P all -S 0/0 -D $IPADDR -W eth0
####/sbin/ipfwadm -I -a accept -P tcp -S 0/0 -D $IPADDR http telnet smtp
auth domain -W eth0

# Accept anything from Linux @ office  (Trusted - tcp UDP and icmp )
# What happens if someone masquerades as myself?  PARANOIA !!!
####/sbin/ipfwadm -I -a accept -P all -S 209.x.x.x  -D 24.x.x.x  -W eth0
#Accept http web request from anybody
####/sbin/ipfwadm -I -a accept -P tcp -S 0/0 -D 24.x.x.x  http auth
domain -W eth0
#
# deny and LOG all tcp from hosts other than those
# specified in the above lines
/sbin/ipfwadm -I -a deny -P tcp -S 0/0 -D 0/0 0:1000 -W eth0 -o
# Outgoing, flush and set default policy to deny.
# -----------------------------------------------
/sbin/ipfwadm -O -f
# default policy deny
/sbin/ipfwadm -O -p deny
# any source going to local interface is valid
/sbin/ipfwadm -O -a accept -W lo
/sbin/ipfwadm -O -a accept -S $IPADDR -D 0/0 -W eth0
# Allows all subnet user to go out
/sbin/ipfwadm -O -a accept -S 0/0 -D 10.0.0.0/24 -W eth1
# catch all rule, all other outgoing is denied and logged.
/sbin/ipfwadm -O -a deny -S 0/0 -D 0/0 -o
# Forwarding, flush and set default policy to deny.
# -------------------------------------------------
/sbin/ipfwadm -F -f
# default policy deny
/sbin/ipfwadm -F -p deny
# Masquerade from local net on local interface to anywhere.
/sbin/ipfwadm -F -a masquerade -S 10.0.0.0/24 -D 0/0 -W eth0
# catch all rule, all other forwarding is denied and logged.
/sbin/ipfwadm -F -a deny -S 0/0 -D 0/0 -o


Paolo Illing
PAGA Software Inc.
21 Abilene Drive,  Toronto,  ON   M9A 2M7
Tel: +1 (416) 232 0711
http://www.paga.com
[EMAIL PROTECTED]




_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to