/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


We are using IP-masq to deliver Internet connectivity to one of our
customers via a DSL line.  This customer relies heavily on ICQ, so as a
result, I have NEC's socks5 daemon running on the masq server.  However,
after I got socks5 up and running, I started getting the following error
in my syslog (IP's changed to protect the innocent) each time I tried to
send an ICQ message from the masqed network, through the firewall to one
of the machines on my LAN:

Jan 18 08:57:03 hostname kernel: IP fw-out rej eth0 TCP 192.168.0.34:27256
192.168.0.15:23964 L=44 S=0x00 I=40065 F=0x0000 T=64

192.168.0.15 is the machine that I sent the ICQ message to.  However,
192.168.0.34 is actually an IP alias on eth0  for a virutal webhost. (it's
eth0:2, to be precise). My eth0 interface is actually 192.168.0.3. It's
for this reason that it was being rejected.  I had rules set up to allow
outgoing traffic on 192.168.0.3 (eth0), but I didn't have rules set up to
allow outgoing traffic on 192.168.0.34 except port 80.  Allowing all
outbound traffic from 192.168.0.34 has fixed the problem, but I can't
understand why it was using the address for eth0:2 instead of eth0.
Incidentally, it seems to use whichever IP address was last configured on
eth0.  If I add an eth0:3, it uses that IP.  Anyway, this sort of bugs me.
I'm able to work around it by adding this address to rc.firewall, but
isn't there any way to force it to use the IP for just plain old eth0?  I
don't know if this is related to IP-masq or socks5, but I thought I'd
throw it out there to see if anyone has seen this before.

Thanks.

Craig

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to