Hi folks!   This will be a long email.  Sorry.
I either do not understand routing, or firewalling, or BOTH.   :-)

My environment now:

Cable modem to Linux eth0  IP 24.x.x.x
Linux box is hosting a few web sites, is running sendmail also for the users
of 10.0.2.x, and DNS

Linux eth1 IP 10.0.0.221
Win 98  IP 10.0.0.223/24   gateway 10.0.0.221

Linux eth2  IP 10.0.1.221
Cisco 760 (home) ISDN router   IP 10.0.1.254   routing 0.0.0/0 to gateway
10.0.2.254

at the other end of the ISDN:

cisco 760 ( pal ) router   IP 10.0.2.254    routing  0.0.0.0/0 to gateway
10,0,1,254
winNT server  IP 10.0.2.10/24 gateway 10.0.2.254
4 more Win95/98 at various IP 10.0.2.x

I have implemented David's suggestions in my rc.firewall, that I include at
the end of this email.

The objective:

Have the users at 10.0.2.x to access the internet (web and POP)
It is NOT important that 10.0.0.223 (my win 98) has access to 10.0.2.10
(remote NT server), but it would be nice to have

The problems and symptoms:

a) Testing from my win98(IP 10.0.0.223)  to outside has no problem. It
always worked.
     Testing from my win98(IP 10.0.0.223): ping 10.0.1.221   ----> Success
     Testing from my win98(IP 10.0.0.223): ping 10.0.1.254  --->   FAIL.
The TCPDUMP of eth1 shows 10.0.0.223 > 10.0.1.254  icmp echo request, but no
echo answer.

b) Testing from the linux console:  Ping 10.0.1.254 (home cisco)    --->
Success
     Testing from the linux console:  Ping 10.0.2.254  (pal cisco)   --->
FAIL  The TCPDUMP of eth0 shows 10.0.0.223 > 10.0.2.254  icmp echo request,
but no echo answer.  I am obviously missing the equivalent of a "route add".


c)  Testing from the cisco (home) :  ping 10.0.1.221   --->  Success
     Testing from the cisco (home) :  ping 24.x.x.1   (my @home
teway)   --->  No answer.  The TCPdump on eth2 does not show anything, nor I
can see any activity on TCPDUMP host 24.x.x.x (my eth0 IP)

d) Testing from the remote win NT box (IP 10.0.2.10):  Ping 10.0.1.254 (the
home cisco) is successful. The pal cisco dials the home cisco who answers
back.
    Testing from the remote winNT box:  Ping 10.0.1.221 (my linux eth2) -
NOT successful.  The TCPDUMP of eth2 shows  10.0.2.10 > 10.0.1.221  icmp
echo request, but no echo answer.
     Testing from the remote winNT box:  Ping 24.x.x.1(my @home gateway)   -
Not successful  The TCPDUMP on eth0 or eth2 does not show anything. The NT
ping shows "desination host unreachable"

References:
The cisco routers are configured exactly as shown in the cisco site at:
http://www.cisco.com/warp/cpropub/67/pcppcucs.html

=====================
here is my rc.firewall
=====================
#!/bin/sh
#
# Last Modified 20 Jul 1998
# Modified June 13 1999 with David Ranch suggestions
#
/sbin/depmod -a
/sbin/modprobe ip_masq_ftp
# /sbin/modprobe ip_masq_raudio
# /sbin/modprobe ip_masq_irc
# /sbin/modprobe ip_masq_cuseeme
# /sbin/modprobe ip_masq_vdolive
#
# IPADDR is the address on eth0 (outside world)
#
IPADDR=`/sbin/ifconfig eth0 | /bin/awk '{
    if( $0 ~ /inet addr:/ ) { match($0,/[0-9]*\.[0-9]*\.[0-9]*\.[0-9]*/);
    print substr($0, RSTART, RLENGTH); }}'`
#
# MASQ timeouts     2 hrs for tcp sessions
#                   10 seconds for traffic after a "FIN" TCP packet is
received
#                   60 seconds for UDP traffic
#
/sbin/ipfwadm -M -s 7200 10 60
#
# Incoming, flush and set default policy to reject.
# -------------------------------------------------
/sbin/ipfwadm -I -f
/sbin/ipfwadm -I -p reject
#
# local NIC (any local PC on network) going anywhereis valid
#
/sbin/ipfwadm -I -a accept -S 10.0.0.0/24  -D 0/0 -W eth1
/sbin/ipfwadm -I -a accept -S 10.0.1.0/24  -D 0/0 -W eth2
/sbin/ipfwadm -I -a accept -S 10.0.2.0/24  -D 0/0 -W eth2
#
# remote NIC (WAN side) any source, going to my ppp IP addr is valid
#
/sbin/ipfwadm -I -a accept -P all -S 0/0 -D $IPADDR -W eth0
#
#  Loopback Interface (127.0.0.1) is valid
#
/sbin/ipfwadm -I -a accept -W lo
#
# Catch all rule. Reject and LOG all tcp from hosts other than those
# specified in the above lines
#
/sbin/ipfwadm -I -a reject -P tcp -S 0/0 -D 0/0 0:1023 -W eth0 -o

#
# Outgoing, flush and set default policy to reject.
# -----------------------------------------------
/sbin/ipfwadm -O -f
/sbin/ipfwadm -O -p reject
#
# loopback interface is valid
#
/sbin/ipfwadm -O -a accept -W lo
#
# Allows all  (LAN) subnet user to go out
#
/sbin/ipfwadm -O -a accept -S 0/0 -D 10.0.0.0/24 -W eth1
/sbin/ipfwadm -O -a accept -S 0/0 -D 10.0.1.0/24 -W eth2
/sbin/ipfwadm -O -a accept -S 0/0 -D 10.0.2.0/24 -W eth2
#
#  Anything else going through the WAN NIC is valid
#
/sbin/ipfwadm -O -a accept -S $IPADDR -D 0/0 -W eth0
#
# catch all rule, all other outgoing is denied and logged.
#
/sbin/ipfwadm -O -a reject -S 0/0 -D 0/0 -o
#
# Forwarding, flush and set default policy to deny.
# ------------------------------------------------
/sbin/ipfwadm -F -f
/sbin/ipfwadm -F -p deny
#
# Enable eth1 and eth2 to communicate within each other
#
/sbin/ipfwadm -F -a accept -W eth1 -D 10.0.1.0/24
/sbin/ipfwadm -F -a accept -W eth2 -D 10.0.0.0/24
#
# Masquerade from local net on local interface to anywhere.
#
/sbin/ipfwadm -F -a masquerade -S 10.0.0.0/24 -D 0/0 -W eth0
/sbin/ipfwadm -F -a masquerade -S 10.0.1.0/24 -D 0/0 -W eth0
#
# catch all rule, all other forwarding is denied and logged.
#
/sbin/ipfwadm -F -a deny -S 0/0 -D 0/0 -o

Thanks


Paolo Illing
PAGA Software Inc.
21 Abilene Drive,  Toronto,  ON   M9A 2M7
Tel: +1 (416) 232 0711
http://www.paga.com
[EMAIL PROTECTED]




_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to