/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */



Hi,

I have IP Masquerading running on a Intel P-100 machine running Redhat 5.1, 
and generally working quite well with the one exception of ftp URLs. 
Whenever I click on an ftp://... URL from within any web browser on any 
client platform, the browser simply waits and eventually times out. HTTP 
URLs work fine. To my surprise, the FTP program works great when used from 
the command line.

I've included below the script which I'm using to set up the masquerade 
rules. It is based upon the one in Paul Sery's Linux Network Toolkit book. I 
believe that I am including the ip_masq_ftp module, but perhaps I'm doing it 
incorrectly. Any help would be greatly appreciated.

Best Regards,

Carl


# begin firewall.rules

 ISP_IP="xxx.xxx.xxx.xxx"
 echo "Setting up firewall rules"
 echo $ISP_IP

# My fixed addresses
   ME="192.168.1.254"
   FIRE_NET="xxx.xxx.xxx.0/24"
   PRIV_NET="192.168.1.0/24"
   ALLIP="0.0.0.0/0"
   HIPORTS="1024:65535"
   PROTOCOLS="pop-3 smtp ftp ftp-data www telnet domain https"

#include needed libs
/sbin/depmod -a
/sbin/modprobe ip_masq_ftp

# Clear out whatever rules are still set
ipfwadm -I -f
ipfwadm -O -f
ipfwadm -F -f

# Start by completely denying any network access.
ipfwadm -I -p deny
ipfwadm -O -p deny
ipfwadm -F -p deny

# Deny spoofed packets.
ipfwadm -I -a deny -V $ISP_IP \
                   -S $FIRE_NET \
                   -D $ALLIP 
ipfwadm -I -a deny -V $ISP_IP \
                   -S $ISP_IP \
                   -D $ALLIP


# Allow unlimited traffic within the local network
# (All all traffic on the ethernet interface - attached to the 
# Linux file/print server. This does not affect the behavior of
# the PPP/Internet connection.)
# 
ipfwadm -I -a accept -V $ME \
                     -S $ALLIP \
                     -D $ALLIP
ipfwadm -O -a accept -V $ME \
                     -S $ALLIP \
                     -D $ALLIP

# Allow outgoing TCP packets for the specified protocols
# I use duplicate rules for both the specific PPP IP address (obtained 
# from the first command line in this script) as well as the firewall 
# subnet. The first rule allows you to access the Internet from the firewall 
# network since outgoing packets use the PPP connection IP as their source
# address (Note that this is superfluous if you follow the instructions 
# in chapter 11 that remove most network applications from the firewall to 
# increase security.) The second rule permits computers on the firewall 
network 
# and the private network to reach the Internet since they arrive at the 
# PPP interface with the source address of the Linux file/print server which
# routes packets from the private network to the firewall network and 
# masquerades them.
ipfwadm -O -a accept -P tcp \
                     -S $FIRE_NET $HIPORTS \
                     -D $ALLIP $PROTOCOLS 
ipfwadm -O -a accept -P tcp \
                     -S $ISP_IP $HIPORTS \
                     -D $ALLIP $PROTOCOLS

# Allow outgoing UDP packets for the specified protocols (name service 
here).
ipfwadm -O -a accept -P udp \
                      -S $FIRE_NET $HIPORTS \
                      -D $ALLIP domain
ipfwadm -O -a accept -P udp \
                      -S $ISP_IP $HIPORTS \
                      -D $ALLIP domain


# Allow the return packets of sessions originating internally for the 
# specified protocols. The -k option allows only those packets with their 
# SYN bit set. When the SYN bit is set, it means that the packet is being 
# returned by a remote process after having originated locally.
ipfwadm -I -a accept -k -P tcp \
                        -S $ALLIP $PROTOCOLS \
                        -D $FIRE_NET $HIPORTS
ipfwadm -I -a accept -k -P tcp \
                        -S $ALLIP $PROTOCOLS \
                        -D $ISP_IP $HIPORTS

# Allow the remote ftp server to initiate a connection back to you. This 
# happens when you issue an ftp command like "dir" or "get" or "put", etc. 
# Note that this is not  necessary if you use the ftp passive mode.
ipfwadm -I -a accept -P tcp \
                     -S $ALLIP ftp-data \
                     -D $FIRE_NET $HIPORTS
ipfwadm -I -a accept -P tcp \
                     -S $ALLIP ftp-data \
                     -D $ISP_IP $HIPORTS

ipfwadm -I -a accept -P udp \
                     -S $ALLIP domain \
                     -D $FIRE_NET $HIPORTS
ipfwadm -I -a accept -P udp \
                     -S $ALLIP domain \
                     -D $ISP_IP $HIPORTS

# Set masquarading rules. (The second rule is necessary if you do not
# set up masquerading on the router - in our case the Linux file/print
# server - between the private and firewall networks. If that is the
# case, you also have to add a route on the firewall server to point
# back to the private network. For example: 
# route add -net 192.168.1.0 gw 192.168.32.254
#

    ipfwadm -F -a masquerade  -S $FIRE_NET -D 0.0.0.0/0
    ipfwadm -F -a masquerade  -S $ISP_IP   -D 0.0.0.0/0
    ipfwadm -F -a masquerade  -S $PRIV_NET  -D 0.0.0.0/0


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/

Reply via email to