/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
I wonder If you guys could give me a hand with something.
I just recently figure out how to get StarFleet Command on
mplayer.com running though a NATing firewall. Said firewall is a Linux
2.2.14 machine. I'm using ipchains and ipmasqadm to create the rules.
Some of them are stock "ipmasq" rules put in place by debian.
With the help off some players on mplayer.com, and a look at the game
on my local network, I noticed it was using ports 23xx UDP rang. It
also seemed to need 47624 UDP. So I created the following, using TCP
as well just in case:
#!/bin/bash
IPMASQADM="/usr/sbin/ipmasqadm"
EIP=$1
IIP=$2
# flush the rule set.
$IPMASQADM portfw -f
# mplayer.com SFC
port=2300
while [ $port -lt 2400 ]
do
$IPMASQADM portfw -a -P tcp -L $EIP $port -R $IIP $port
$IPMASQADM portfw -a -P udp -L $EIP $port -R $IIP $port
port=$((port+1))
done
# Dirrect play uses port 47624 tcp/udp
$IPMASQADM portfw -a -P udp -L $EIP $port -R $IIP 47624
$IPMASQADM portfw -a -P tcp -L $EIP $port -R $IIP 47624
--8<--
This seemed to do the trick. However, I noticed sometime later that my
firewall machine was assigning ports in the that 23xx rang to outgoing
connections, in this case it was fetchmail. Needless to say I didn't
get any mail for the rest of the night...
My questions are:
How can I tell the firewall machine not to use those ports while I'm
forwarding them?
Is there a better way to enter the rules? I'd rather do it with IP
chains than with a shell-script loop.
Is there anyway to have multiple machines behind the NAT work in a
pear-to-pear game setup like SFC?
Thanks!
--
Matt Valites ([EMAIL PROTECTED])
The Axium - http://www.axium.net
We're not elitist. We really are better than you.
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.