/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Actually, I'm running kernel 2.0.36 and ipfwadm.  Here's my socks5.conf
file:

auth 10.0.4. - n
auth 10.0.5. - n
permit - - 10.0.4. - - -
permit - - 10.0.5. - - -
deny - - - - - -

I got this from the list archives, and socks seems to work right...sort
of.

Here's my ifconfig:

lo        Link encap:Local Loopback
          inet addr:127.0.0.1  Bcast:127.255.255.255  Mask:255.0.0.0
          UP BROADCAST LOOPBACK RUNNING  MTU:3584  Metric:1
          RX packets:1106 errors:0 dropped:0 overruns:0 frame:0
          TX packets:1106 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0
 
eth0      Link encap:Ethernet  HWaddr 00:A0:24:CE:F1:90
          inet addr:192.168.0.3  Bcast:192.168.0.255 Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:613991 errors:0 dropped:0 overruns:0 frame:0
          TX packets:229797 errors:0 dropped:0 overruns:0 carrier:0
          collisions:22322
          Interrupt:12 Base address:0xe400
 
eth0:1    Link encap:Ethernet  HWaddr 00:A0:24:CE:F1:90
          inet addr:192.168.0.32  Mask:255.255.255.0
          UP RUNNING  MTU:1500  Metric:1
          RX packets:1 errors:0 dropped:0 overruns:0 frame:0
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0
 
eth0:2    Link encap:Ethernet  HWaddr 00:A0:24:CE:F1:90
          inet addr:192.168.0.34  Mask:255.255.255.0
          UP RUNNING  MTU:1500  Metric:1
          RX packets:2 errors:0 dropped:0 overruns:0 frame:0
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0
 
eth1      Link encap:Ethernet  HWaddr 00:E0:29:3D:9C:7B
          inet addr:10.0.4.1  Bcast:10.0.4.255  Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:148024 errors:0 dropped:0 overruns:0 frame:0
          TX packets:21942 errors:0 dropped:0 overruns:0 carrier:0
          collisions:2
          Interrupt:10 Base address:0xdc00
 
eth2      Link encap:Ethernet  HWaddr 00:E0:29:3D:A0:E5
          inet addr:10.0.5.1  Bcast:10.0.5.255  Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:8921 errors:0 dropped:0 overruns:0 frame:0
          TX packets:11073 errors:0 dropped:0 overruns:0 carrier:0
          collisions:5
          Interrupt:9 Base address:0xe000


eth1 and eth2 are networks being masq'ed.  The external IP address should
be 192.168.0.3 (eth0), but for some reason it's using 192.168.0.34
(eth0:2).  If I take eth0:2 down, then it starts using 192.168.0.32
(eth0:1).  And of course if I add an eth0:3, it starts using that one.  It
seems to want to use whatever IP was set up last on eth0, even if it's a
virtual IP.

I think that this is a socks5 issue.  I tried using FTP from a machine
behind the masq server, and connected to my FTP server outside the masq
server.  The log entry says that it came from 192.168.0.3 (eth0), so it
looks like masq is using the right Interface.  It's just ICQ connects
going through socks5 that seem to be using eth0:2.

Any ideas?

Craig


On Tue, 18 Jan 2000, Gregory Leblanc wrote:

> Craig Baird wrote:
> > 
> > /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
> > 
> > We are using IP-masq to deliver Internet connectivity to one of our
> > customers via a DSL line.  This customer relies heavily on ICQ, so as a
> > result, I have NEC's socks5 daemon running on the masq server.  However,
> > after I got socks5 up and running, I started getting the following error
> > in my syslog (IP's changed to protect the innocent) each time I tried to
> > send an ICQ message from the masqed network, through the firewall to one
> > of the machines on my LAN:
> > 
> > Jan 18 08:57:03 hostname kernel: IP fw-out rej eth0 TCP 192.168.0.34:27256
> > 192.168.0.15:23964 L=44 S=0x00 I=40065 F=0x0000 T=64
> > 
> > 192.168.0.15 is the machine that I sent the ICQ message to.  However,
> > 192.168.0.34 is actually an IP alias on eth0  for a virutal webhost. (it's
> > eth0:2, to be precise). My eth0 interface is actually 192.168.0.3. It's
> > for this reason that it was being rejected.  I had rules set up to allow
> > outgoing traffic on 192.168.0.3 (eth0), but I didn't have rules set up to
> > allow outgoing traffic on 192.168.0.34 except port 80.  Allowing all
> > outbound traffic from 192.168.0.34 has fixed the problem, but I can't
> > understand why it was using the address for eth0:2 instead of eth0.
> > Incidentally, it seems to use whichever IP address was last configured on
> > eth0.  If I add an eth0:3, it uses that IP.  Anyway, this sort of bugs me.
> > I'm able to work around it by adding this address to rc.firewall, but
> > isn't there any way to force it to use the IP for just plain old eth0?  I
> > don't know if this is related to IP-masq or socks5, but I thought I'd
> > throw it out there to see if anyone has seen this before.
> 
> This sounds suspiciously similar to the problem that Doug Apel was
> having before the end of the year.  I'm curious as to whether you're
> running 2.2.14, or an earlier kernel.  (my personal guess is that it's
> 2.2.14...).  Let us know which kernel, and we'll see what we can come up
> with,
>       Greg

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to