/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


I just doce into the same subject over the last 2 weeks, and the
before mentioned IP Masq mini-HOWTO(which now is an official full
HOWTO) will introduce you to all the terms and necessary knowledge to
understand IP Masquerading and firewall design. After the introductory
examples it will suggest reading the real world application of these
lessons in:
http://members.home.net/ipmasq/ipmasq-HOWTO-1.79-6.html#Strong-IPCHAIN
S-Rulesets
Which will give you step by step help in building powerfull
masuerading/forwarding/anything you want to do rulesets. But, it
doesn't stop there, the author D. Ranch has laid out what is close to
the definitive lessons in masquerading/ security firewalls in :

http://www.ecst.csuchico.edu/~dranch/LINUX/TrinityOS.wri

All of it is excellent reading and you will probably end up applying
many of his more advanced rules to protect your LAN. Best of all, it
is written so that anyone with a basic knowledge of IP addressing can
understand.

Good reading

Victor

----- Original Message -----
From: Gregory Leblanc <[EMAIL PROTECTED]>
To: Masquerade List (E-mail) <[EMAIL PROTECTED]>
Cc: 'Adam' <[EMAIL PROTECTED]>
Sent: Monday, November 22, 1999 10:27 PM
Subject: RE: [Masq] Deep inside protocol


> /* HINT: Search archives @ http://www.indyramp.com/masq/ before
posting! */
>
>
> > -----Original Message-----
> > From: Adam [mailto:[EMAIL PROTECTED]]
> > Sent: Monday, November 22, 1999 9:13 PM
> > To: [EMAIL PROTECTED]
> > Subject: [Masq] Deep inside protocol
> >
> >
> > /* HINT: Search archives @ http://www.indyramp.com/masq/
> > before posting! */
> >
> >
> > Hi
> >
> > I am electronic engineer and I started to think about small
> > masquerading box.
> >
> > Internet will be "supplied" by RS-232 running at 115200bps,
> > full duplex
> > with Point to Point protocol.
>
> Some of us call this a "modem" connection.  (bear with me, I just
finished
> beating the tar our of some files on Solaris, that are designed for
GNU
> systems)
>
> >
> > I plan to use Ethernet controller to make access for _only_ 4
"hidden"
> > machines connected to the local area network. Something like that:
> >
> > 192.168.0.2
> > 192.168.0.3    LAN       |----------My box --------------------|
> > 192.168.0.4 <==========> 192.168.0.1-- 212.244.xxx.xxx ==
> > RS-232--->internet
> > 192.168.0.5
> >
> > Where can I find more detailed information about all rules of
> > masquerading
> > like
>
> The FIRST place to look is the ipmasq mini-howto (which isn't mini),
on
> http://ipmasq.cjb.net/  At the same time I would get a linux box,
and
> install the latest kernel, and latest ipchains, and possibly latest
> ipmasqadm tools.  Read the man pages, for some additional
information not in
> the howto.  Then, if you're REALLY ambitions, head for the kernel
source,
> and read it to find exactly what it all does.  :)  None of these are
> available in PDF that I know of, but many web pages have this info.
>
> >
> > 1. Detailed rules of port assigning/changing  when packet goes
through
> > masquerade
>
> I suspect that this would take reading the kernel documentation, or
the
> sources.  I don't think it's in the man pages.
>
> > 2. What to do with normal TCP and what to do with UDP and others ?
> > 3. What will happen if sent request will never come back
>
> It will time out.
>
> > 4. Which fields of TCP (and others) packet should be
> > processed and what are
> > all rules.
>
> The rules are waht you make them.  Have fun, enjoy your reading.
> Greg
>
> _______________________________________________
> Masq maillist  -  [EMAIL PROTECTED]
> Admin requests can be handled at
http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
>
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to