/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Matt Valites <[EMAIL PROTECTED]> wrote:
>
> This seemed to do the trick. However, I noticed sometime later that
> my firewall machine was assigning ports in the that 23xx rang to
> outgoing connections, in this case it was fetchmail. Needless to say
> I didn't get any mail for the rest of the night...
Ouch.. I really thought that "autofw" was the subsystem that showed
this problem, and that it was "portfw" that managed to avoid it.
Perhaps that's not the case..?
In a 2.2 kernel, you can control which port numbers are assigned to
local programs that don't bind a specific port (and hardly any do).
# cat /proc/sys/net/ipv4/ip_local_port_range
1024 4999
This tells you that a local process that binds a wildcard socket will
receive a port somewhere between 1024 4999. If you don't want it to use
that range, enter some different numbers:
# echo 3000 4999 > /proc/sys/net/ipv4/ip_local_port_range
That's only 2000 ports, but if your firewall doesn't make many local
connections, it will probably be fine. Or you could redirect to another
range, such as 8000-12000. Whatever you feel comfortable with. :)
> Is there a better way to enter the rules? I'd rather do it with IP
> chains than with a shell-script loop.
I have seen people use port-range syntax on portfw commands, but it
doesn't work when I try it. Maybe I just have an old version. Or maybe
people are posting off the top of their heads, rather than actually
trying out their examples. :)
--
[EMAIL PROTECTED] (Fuzzy Fox) || "Good judgment comes from experience.
sometimes known as David DeSimone || Experience comes from bad judgment."
http://www.dallas.net/~fox/ || -- Life Lessons
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.