/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Thanks for the suggestions.  Some of these I had already already tried, and
others I tried at your suggestion.  Unfortunately, none yielded any more
success (but hopefully the results will provide more insight).

"Jose M. Sanchez" wrote:
> 
> Make sure your Linux box can resolve hostnames FIRST before you go any
> farther...
> 
> Try
> 
> "nslookup www.redhat.com"
> 
> If you get back an IP number, you are locally resolving correctly, (which I
> doubt).

Been there, done that, works.  As I said in my orignial post, net access
from the linux box appears to work perfectly (name lookup, http, telnet,
ping, etc)  That's part of what is so frustrating.

> Then run NSLOOKUP and set the "server" to be the IP address which your
> Windblows machines are using.. and try again.

You mean the inside IP of the linux box?  I tried doing "nslookup
www.redhet.com 192.168.0.1", and that failed because it said it couldn't
find the hostname for the server "192.168.0.1" (that's the internal IP of
the linux box), but when I went into interactive mode (i.e. just typing
"nslookup") and did "server 192.168.0.1" then "www.redhat.com" that worked
fine.

> I'll bet you didn't enable DNS resolution explicitly for the ethernet card
> your workstations are talking to... in other words, BIND is listening on
> "localhost" but not on eth1, or something like this...

Hmm... can you point me to instructions on how to check that/set it up?  (is
the bind man page sufficient?)

> If you are using the DHCP CLIENT in Linux, make sure that it is properly
> modifying the /etc/resolv.conf file every time you boot up your computer.

Actually, and this may be the source of my problem, what I've been doing is
setting up DHCP on the windows machine, allowing it to do all the DHCP
stuff, then using winipconfig to get all of the addresses.  Then I set up
networking on the linux box to match all of the settings (including the MAC
address) and switch it so that the linux box is connected to the cable
modem.  As far as the linux box is concerned and as long as DHCP doesn't try
to change my IP, I have a temporarily static IP.  Then I change windows
network setting to the "internal" network settings and reboot.  I think this
is working, because from the linux box out to the internet, everything seems
fine.

> Next try entering the IP address of a web page directly into the browser.
> 
> Does it come up?
> 
> If so, http is being masq'd properly...

Nope, as I said in my first post, web browsing w/ hostnames in Netscape (on
the Winblows box) hangs at "looking up [hostname]" and browsing with IP
hangs at "host contacted, waiting for reply".  It's making some kind of
connection, because I can see the "domain" or "www" entry in the MASQ table.

> Are your Windows machines pointing at your ISPs or your Linux box for DNS
> resolution? You might want to set up a caching nameserver, and point your
> Winblows machines at your Linux box... (remember to ENABLE your ethernet
> card's ability to resolve... you use...)
>
> Until you have some sort of resolver/DNS running Linux will NOT resolve
> addresses for your Masq'd clients...

As I said above, I've tried it both ways...  I'm running BIND/named.

> Remember NAME resolution is not affected by Masq if Linux is performing the
> name resolution, but Linux must permit DNS queries on the INTERFACE that
> your Winblows machines are talking to.
> 
> If you are letting the ISP's DNS do name resolution for you, and name
> resolution does not work, then something is amiss with your rules, and you
> are inadvertantly blocking DNS queries...

If that's the problem, I'm missing it.  I'm using the simple rc.firewall
ruleset and checking the rules with "ipchains -L" shows that Input and Ouput
are "ACCEPT" and Forward is "DENY" with one MASQ entry for the Winblow's
box's IP.  The default Debian setup does do something with the portmap... in
/etc/hosts.deny there is a line "ALL: PARANOID" which I am suspicious of,
but I don't know enough about the portmapper...

> BTW: Do you have your cable modem plugged into a common hub or directly into
> a second interface on your Linux box?

Directly into the second interface on the Linux box.

> I haven't use RoadRunner, but I've set up various cable modem Linux Masq
> machines for people, and all have so far worked... even oddballs, like
> dialup upstream connections, work fine.
> 
> BTW: It pays to have eth0 be the side that talks to the Cable modem, and
> eth1 be your local lan... which ideally you should set up during the
> installation...
> 
> This permits the scripts to set things up correctly at boot... you could
> manually modify things around this, but in several setups I've found this to
> be easier.

I do have it set up that way.  (not a conscious choice, I guess it just
worked out that way).  Thanks a bunch.  That was one heck of an email.  Do
any of my answers spark any new suggestions?  Another thing I found odd, is
that doing the ifconfig for eth0 and eth1 seems to automatically add the
route to the routing table.  Is it supposed to do this, or is there some
kind of init script I'm missing that's doing this behind my back?

Bob

> -JMS
> [EMAIL PROTECTED]
> 
> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf
> Of Bob Schmanski
> Sent: Tuesday, February 29, 2000 3:14 AM
> To: Michael Best
> Cc: [EMAIL PROTECTED]
> Subject: Re: [Masq] IP Masquerading ALMOST works
> 
> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
> 
> Thanks, I checked it out, and timeouts don't seem to be the problem.
> "ipchains -L -v" reports 0 packets and 0 bytes denied for forwarding (i.e.
> all were masq'ed).  As for the whole DNS thing, I have tried setting my
> Win98 machine to use the ISP dns IPs and have tried setting up my linux box
> as a forwarding name server and pointing my Win98 box to it for DNS.  Both
> produced identical results.  Has anyone on this list succefully set up IP
> MASQ with Media One's Road Runner cable modem service?
> 
> Thanks,
> Bob
> 
> Michael Best wrote:
> >
> > On 27 Feb 2000, Bob Schmanski wrote:
> >
> > > specifically, from the Win98 box I can ping any static IP on the net,
> but
> > > dns lookup fails (I can't ping any hostnames).  I can telnet to static
> IP's
> > > but sometimes I don't get a login prompt, and on the machines that I do
> get
> > > a login prompt and have login access to, I can log in, but never get a
> UNIX
> > > prompt.  I cannot browse (www/http) to IPs or hostnames.  Hostnames fail
> dns
> > > lookup and IP's hang at "host contacted, waiting for reply".  From the
> >
> > Someone else suggested that this is a DNS problem.  I'm not exactly sure
> what
> > the problem is, but it is certainly not a DNS issue.  One possibility is
> that
> > your masquerading entries are timing out too quickly.  Type
> "ipchains -L -v"
> > after doing some tests and check the packet counts.  If you are seeing
> > something like this: "Chain forward (policy DENY: 1856 packets, 350238
> > bytes)", you probably have the timeout problem.
> >
> > -- Michael Best
> 
> _______________________________________________
> Masq maillist  -  [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS
> INCLUDES UNSUBSCRIBING!
> or email to [EMAIL PROTECTED]
> 
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to