/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Hello,
I'm new to this list -- this is my first post. I got IP MASQ working on a
486 (running Red Hat Linux 6.0) -- it has two network cards, one going to my
cable modem, the other going to my LAN (hub). It works great -- not perfect
with all services of course, but it still works great. Now I just want to
address some of my security concerns:
[ /etc/rc.d/rc.local ]
[...]
ipchains -P forward DENY
ipchains -A forward -s 10.0.0.0/255.0.0.0 -j MASQ
[...]
Is there anyway I can tell ipchains to only Forward/MASQ on only a certain
network device, such as eth0? I mean that way, even if someone spoofs their
IP or some staff within @Home that is using a LAN Address in the
10.0.0.0/255.0.0.0 block can't MASQ behind my box, since they are not
physically hooked up to my LAN -- otherwise they could set my real IP as a
gateway and MASQ themselves behind me -- right? Does this make sense? I've
tried some variations of ipchains and I couldn't get it to work -- help
please.
Also, what else could one do to "beef up" security while using IP MASQ?
Thanks a bunch!
Sincerely,
Pankaj Arora
CEO & Chairman
www.paware.com
www.paware.com/pasoft/
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/