Subject: IPCHAINS/IPMASQADM Problem
Just FYI for most of you. I got my FTP forwarding completed. But the one
caveot is that it only works across my MASQed interfaces.
Here's what I got:
167.16.1.11 ------|
mach 1 |
|
167.16.1.219 ------|------- 167.16.1.30/192.168.0.100 -------
192.168.0.110
mach 2 mach 3 mach 4
Machine 3 is the chains machine. Token ring interface is the 167.16.1.30
and
the ethernet interface is 192.168.0.100. Here is the IPCHAINS output:
[root@linux01 /]# ipchains -L
Chain input (policy ACCEPT):
Chain forward (policy DENY):
target prot opt source destination ports
MASQ all ------ 192.168.0.0/24 anywhere n/a
MASQ all ------ anywhere 192.168.0.0/24 n/a
Chain output (policy ACCEPT):
Not bad... Simply MASQing everything across the two subnets. It works
well.
I have to add a ROUTE on Machine 2 to tell it how to get to the 192.168.0.x
subnet when accessing them directly. The problem is that machines on the
left don't really know there are any machine on the right until you add a
route to them. Simple.
Here is what I did with IPMASQADM:
[root@linux01 /]# ipmasqadm portfw -l
prot localaddr rediraddr lport rport pcnt pref
TCP linux01.fdcsg.1dc.com 192.168.0.110 ftp ftp 10
10
This on the other hand DOES NOT need a route because all the intereaction is
with the CHAINS machine. If you FTP from machine 2 to machine 3 you end up
on Machine 4 above. The return port 20 is MASQed through machine 3 so
machine 2 has no idea its getting forwarded. Neat. (BTW... This works with
telnet (23) too!)
BUT.... This is not what I really had in mind when starting this.
I wanted to FTP to machine 3 and end up on machine 1. Or telnet to machine
3
and end up on machine 1. The problem is to the MASQed machine (destination)
the packet might as well have come directly from the client. So it tries to
write it directly back to the client therefore bypassing the MASQ on the way
back.
For instance if I had forwarded packets from machine 3 to machine 1. I
would
telnet from machine 2 to machine 3 (which then gets forwarded to machine 1)
the packets get forwarded...but I don't get ANYTHING back!
I have no idea. Here is the IPCHAINs I tried:
[root@linux01 /]# ipchains -L
Chain input (policy ACCEPT):
Chain forward (policy DENY):
target prot opt source destination ports
MASQ tcp ------ 167.16.1.0/24 anywhere any -> any
MASQ tcp ------ anywhere 167.16.1.0/24 any -> any
Chain output (policy ACCEPT):
And the IPMASQADM would then be this:
[root@linux01 /]# ipmasqadm portfw -l
prot localaddr rediraddr lport rport pcnt pref
TCP linux01.fdcsg.1dc.com 167.16.1.11 ftp ftp 10
10
Right?
Well, all I get when I FTP from machine 2 to machine 3 is nothing....
Now here is a clue:
[root@linux01 /]# ipchains -M -L
IP masquerading entries
prot expire source destination ports
TCP 00:59.28 167.16.1.11 NTWSMATT.fdcsg.1dc.com ftp (21) -> 1288
This is what I get when it times out. These are the current MASQs taking
place. Neat function.
Here is what I get when it works the first way (across the NICs):
[root@linux01 /]# ipchains -M -L
IP masquerading entries
prot expire source destination ports
TCP 119:52.15 192.168.0.110 NTWSMATT.fdcsg.1dc.com ftp (21) -> 1289
I have no idea what the far right number is...but it seems to increment one
every MASQ that takes place.
Anyone have any ideas on this? I'm open to suggestions on how to forward
ports across ONE NIC...not TWO.
-------------------------------------------
Provided to you by Matt Hrynkow
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]