I just recently was looking through the masq-archives and came across
the Loose-UDP patch, which should fix up Starcraft for me (yay!).  One
of the things mentioned was that I would need to use ipportfw rather
than ipautofw (and looking through the descriptions of both, I have
realized that it is better suited to what I am doing anyway.)  But I
have run into some difficulty.

+---------+          +----------------+            +------------------+
|   PPP   |          |  Linux 2.0.36  |            |                  |
| dial-up |<-------->|ppp0            |            | Internal net     |
+---------+          |(dynamic)       |            | 192.168.112.0/24 |
                     |            eth1|<---------->|                  |
                     | 192.168.112.254|            +------------------+
                     +----------------+

(The reason it's eth1 is that the machine used to have another NIC as
eth0 and masqueraded across that, back when I was in a college dorm that
was wired.  I pulled one of the NICs at random to use in another machine
and was too lazy to change the init scripts since I had masq set up to
use eth1 for the 'internal' net already.)

What I want to do is to allow multiple hosts behind the masq/firewall to
be able to play on battle.net et al.  Now, only one person can use it at
once - a limitation of the game - but I didn't want to have to manually
log in and change the rules for each machine, and I had trouble using
ipautofw's "control port" feature.  So, since I have samba running on
the box, I set up a quick script to process a winpopup message from a
client.  This runs as the 'message command' in smb.conf.

--------
#!/bin/sh
# smbmsg
#
# $1 = input file
# $2 = client IP address
# $3 = client netbios name

read line < "$1"
if [ "$line" = "battle.net" ];
then
    # clear old entries
    /usr/local/samba/lib/ipautofw -F
    # battle.net
    /usr/local/samba/lib/ipautofw -A -r tcp 6112 6112 -h "$2"
    /usr/local/samba/lib/ipautofw -A -r udp 6112 6112 -h "$2"
    # MtG on TEN
    /usr/local/samba/lib/ipautofw -A -r tcp 14000 14000 -h "$2"

    echo "Battle.net connections are now forwarded to $3 at $2." |
        /usr/local/samba/bin/smbclient -U BCARTER5 -I "$2" -M "$3"
# elif [ "$line" = "TEN" ];
# then
#     echo "TEN connections are now forwarded to $3 at $2." |
#       /usr/local/samba/bin/smbclient -U BCARTER5 -I "$2" -M "$3"
fi

rm "$1"
--------

What I would like to do is convert this to use ipportfw. This should
allow me to separate the two services - I had to link them together
since I flushed the rules (I couldn't think of an easy way to delete the
old rules without parsing /proc/net/ip_autofw and I was not ready to
spend that kind of effort on the problem.)

But, since I have a dynamic IP address on ppp0, I don't know what to put
in for the ipportfw redirection.  I have the ppp link set up to redial
so it's always connected, but the way it worked before was once you sent
the message, your machine was the default redirect host until someone
else switched it to them.

Would it be possible to modify the ipportfw program to accept an
interface rather than an address?  If I could tell it ppp0, that would
fix the problem for me.  Somehow I don't think putting in the address of
eth1 is going to work.  Ipportfw (as I understand) works within the masq
rules, so I would think that it would be possible to specify an
interface since that is possible with ipfwadm.

On a slight tangent, is it recommended to specify the interface or the
address with ipfwadm?  The rules I have been using used the interface
(with -W), but I could not find any recommendations one way or the other
(except as it applies to IP spoofing where addresses are on the wrong
interface.)

As I see it, unless this is possible, I have two choices:

 1) modify the script to get the inet addr for ppp0 from the output of
    ifconfig

 2) run the ipportfw rules along with the firewall rules at ip-up time.

The problem with 1) is that once the ppp link times out, the forwarding
is no longer valid, meaning that the Windows client will have to run the
messaging every time they want to play, and (possibly) leaving stale
forwarding entries in the table from old IP addresses.

The problem with 2) is that I can only forward to a single masq'ed host,
which gets me back where I started originally.

-- 
-Ben Carter
Human beings, who are almost unique in having the ability to learn from
the experience of others, are also remarkable for their apparent
disinclination to do so. - Douglas Adams, "Last Chance to See" 


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to