/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Nick Urbanik <[EMAIL PROTECTED]> wrote:
>
> modprobe ip_masq_ftp
> modprobe ip_masq_raudio
> ipchains -M -S 7200 10 60
> ipchains -P forward DENY
> ipchains -A forward -l -s 172.160.0.1 -j MASQ
> but still no joy.
Does your route table point traffic in the correct direction, both ways?
Is IP forwarding turned on in /etc/sysconfig/network?
> 1. What is the right way to do it?
What you've got above looks okay, I guess. Usually you want to specify
a network with -s, rather than just a single IP, but it should work, as
long as that's your IP address.
> 2. What am I doing wrong?
Dunno.
> 3. Why can't I use -l with ipchains -P forward DENY? Or if I can,
> how?
You just can't. :)
You can simply add a catch-all rule at the end of the chain, that denies
and logs the packet.
ipchains -A forward -j DENY -l
> 4. Why am I seeing nothing logged?
Either because of the above, or because you didn't enable IP forwarding,
so the forward chain doesn't get processed at all.
> 5. Since the modules all load happily, and there are no other error
> messages when I enter these ipchains commands, I assume the kernel
> is compiled with the right options.
Sure.
> 6. How can I tell if the kernel is compiled with support for IP
> masquerade?
You'll find out when the ipchains command fails, I guess.
Some time has passed since your post. Is it working now?
--
[EMAIL PROTECTED] (Fuzzy Fox) || "Nothing takes the taste out of peanut
sometimes known as David DeSimone || butter quite like unrequited love."
http://www.dallas.net/~fox/ || -- Charlie Brown
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/