/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */



Hello,

I'm new to this list -- this is my first post.  I got IP MASQ working on a
486 (running Red Hat Linux 6.0) -- it has two network cards, one going to my
cable modem, the other going to my LAN (hub).  It works great -- not perfect
with all services of course, but it still works great.  Now I just want to
address some of my security concerns:

[ /etc/rc.d/rc.local ]

[...]
ipchains -P forward DENY
ipchains -A forward -s 10.0.0.0/255.0.0.0 -j MASQ
[...]

Is there anyway I can tell ipchains to only Forward/MASQ on only a certain
network device, such as eth0?  I mean that way, even if someone spoofs their
IP or some staff within @Home that is using a LAN Address in the
10.0.0.0/255.0.0.0 block can't MASQ behind my box, since they are not
physically hooked up to my LAN -- otherwise they could set my real IP as a
gateway and MASQ themselves behind me -- right?  Does this make sense?  I've
tried some variations of ipchains and I couldn't get it to work -- help
please.

Also, what else could one do to "beef up" security while using IP MASQ?

Thanks a bunch!

Sincerely,

Pankaj Arora
CEO & Chairman
www.paware.com
www.paware.com/pasoft/




_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/

Reply via email to