On 21 Jun 99, at 12:23, Rod Moffitt wrote about
    "[Masq]  Masq&Diald: When 'initial' ":

| Masq&Diald: When 'initial' traffic that brings up link is UDP kernel DOES
| not masq - it merely forwards...

I don't see any evidence of that.

|...
| Now Masquerading did work for all packet types from the firewall machine.

When you run from the firewall machine, you are not using masquerade 
at all.

|...
| Anyone have an idea?
| 
| Jun 19 20:12:32 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61232 A.B.C.D:53 L=65 
|S=0x00 I=4096 F=0x0000 T=31
| Jun 19 20:12:47 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61233 E.F.G.H:53 L=65 
|S=0x00 I=4352 F=0x0000 T=31
| Jun 19 20:13:02 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61232 A.B.C.D:53 L=65 
|S=0x00 I=4608 F=0x0000 T=31
| Jun 19 20:13:22 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61233 E.F.G.H:53 L=65 
|S=0x00 I=4864 F=0x0000 T=31

W.X.Y.Z is your public IP, right?  So the packets are being properly 
masqueraded, but they are then rejected by your *output* filter.

| Here are my masquerading rules:
| 
| ipfwadm -F -f
| ipfwadm -F -p deny
| 
| echo "masquerade-forwarding from $PRIVATE_NET"
| ipfwadm -F -a accept -m -W $PUBLIC_INT -S $PRIVATE_NET
| 
| echo "masquerade-forwarding on $DIALD_INT from $PRIVATE_NET"
| ipfwadm -F -a accept -m -W $DIALD_INT -S $PRIVATE_NET
| 
| ipfwadm -F -a deny -o

What is $PUBLIC_INT -vs- $DIALD_INT?  More important, what are your 
output rules?

- Fred Viles <mailto:[EMAIL PROTECTED]>




_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to