On 21 Jun 99, at 12:23, Rod Moffitt wrote about
"[Masq] Masq&Diald: When 'initial' ":
| Masq&Diald: When 'initial' traffic that brings up link is UDP kernel DOES
| not masq - it merely forwards...
I don't see any evidence of that.
|...
| Now Masquerading did work for all packet types from the firewall machine.
When you run from the firewall machine, you are not using masquerade
at all.
|...
| Anyone have an idea?
|
| Jun 19 20:12:32 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61232 A.B.C.D:53 L=65
|S=0x00 I=4096 F=0x0000 T=31
| Jun 19 20:12:47 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61233 E.F.G.H:53 L=65
|S=0x00 I=4352 F=0x0000 T=31
| Jun 19 20:13:02 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61232 A.B.C.D:53 L=65
|S=0x00 I=4608 F=0x0000 T=31
| Jun 19 20:13:22 router kernel: IP fw-out deny ppp0 UDP W.X.Y.Z:61233 E.F.G.H:53 L=65
|S=0x00 I=4864 F=0x0000 T=31
W.X.Y.Z is your public IP, right? So the packets are being properly
masqueraded, but they are then rejected by your *output* filter.
| Here are my masquerading rules:
|
| ipfwadm -F -f
| ipfwadm -F -p deny
|
| echo "masquerade-forwarding from $PRIVATE_NET"
| ipfwadm -F -a accept -m -W $PUBLIC_INT -S $PRIVATE_NET
|
| echo "masquerade-forwarding on $DIALD_INT from $PRIVATE_NET"
| ipfwadm -F -a accept -m -W $DIALD_INT -S $PRIVATE_NET
|
| ipfwadm -F -a deny -o
What is $PUBLIC_INT -vs- $DIALD_INT? More important, what are your
output rules?
- Fred Viles <mailto:[EMAIL PROTECTED]>
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]