I assume that 192.168.1.1 is your INTERNAL NIC.
I would start by flushing the rules and then rejecting all incoming on the
INTERNAL NIC,
rather than rejecting only those 4 IP's.
Initial flushing is good, as it allows you to re-execute the rc.firewall
script without rebooting.
Then , I believe, you are missing all the OUTGOING rules.
Perhaps you can use my script (see recent "Over my head.... please help),
which is at the end of the e-mail and well commented to re-create yours.
(delete the references to my eth2 NIC)
Paolo Illing
PAGA Software Inc.
21 Abilene Drive, Toronto, ON M9A 2M7
Tel: +1 (416) 232 0711
http://www.paga.com
[EMAIL PROTECTED]
----- Original Message -----
From: Rich Eicher <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, June 17, 1999 7:25 AM
Subject: [Masq] ipfwadm help
>
> Folks;
>
> I'm having a bit of a problem with some ipfwadm rules i have in place at a
> client site.
>
> They have a privately numbered lan with 4 machines on static IP addresses.
> Those machines are to have access to the local lan ,DNS and two web sites
only.
>
> Here is what I have in place now that doesn't seem to work:
>
> echo "Loading Masq Modules"
> modprobe ip_masq_ftp
> modprobe ip_masq_raudio
> modprobe ip_masq_irc
>
> echo "Starting IP Forwarding"
> ipfadm -F -p deny
> ipfwadm -F -a m -S 192.168.1.0/24 -D 0.0.0.0/0
>
>
> #
> # Here are the rules for blocking access to the front desk machines
> # that are on static IP addresses.
> #
> # The following IP addresses should have restricted access:
> # 192.168.1.72
> # 192.168.1.73
> # 192.168.1.74
> # 192.168.1.75
> #
>
>
> # Reject and log static IP machines and block access to anywhere.
> ipfwadm -I -a reject -V 192.168.1.1 -S 192.168.1.72/32 -D 0.0.0.0/0 -o
> ipfwadm -I -a reject -V 192.168.1.1 -S 192.168.1.73/32 -D 0.0.0.0/0 -o
> ipfwadm -I -a reject -V 192.168.1.1 -S 192.168.1.74/32 -D 0.0.0.0/0 -o
> ipfwadm -I -a reject -V 192.168.1.1 -S 192.168.1.75/32 -D 0.0.0.0/0 -o
>
> # Allow static IP machines. Going anywhere on the local network is valid.
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.72/32 -D 192.168.1.0/24
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.73/32 -D 192.168.1.0/24
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.74/32 -D 192.168.1.0/24
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.75/32 -D 192.168.1.0/24
>
> # Allow static IP machines. Going to www.crmetroymca.org is valid.
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.72/32 -D 206.26.71.24/32
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.73/32 -D 206.26.71.24/32
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.74/32 -D 206.26.71.24/32
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.75/32 -D 206.26.71.24/32
>
> # Allow static IP machines. Going to www.jointplanning.com is valid.
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.72/32 -D 205.252.23.37/32
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.73/32 -D 205.252.23.37/32
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.74/32 -D 205.252.23.37/32
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.75/32 -D 205.252.23.37/32
>
> # Allow static IP machines. Going to ns1.mwaccess.net is valid.
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.72/32 -D 206.26.71.5/32
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.73/32 -D 206.26.71.5/32
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.74/32 -D 206.26.71.5/32
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.75/32 -D 206.26.71.5/32
>
> # Allow static IP machines. Going to ns2.mwaccess.net is valid.
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.72/32 -D 206.26.71.6/32
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.73/32 -D 206.26.71.6/32
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.74/32 -D 206.26.71.6/32
> ipfwadm -I -a accept -V 192.168.1.1 -S 192.168.1.75/32 -D 206.26.71.6/32
>
>
> What am I doing wrong here?
> Is it the order they are in?
>
> Any help would be greatly appreciated.
>
> Thanks
>
>
>
>
>
>
> _______________________________________________
> Masq maillist - [EMAIL PROTECTED]
> http://tiffany.indyramp.com/mailman/listinfo/masq
> Admin requests can be handled by web (above) or
[EMAIL PROTECTED]
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]