/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


                my rc.firewall looks similiar to:

                PATH=/sbin:/bin:/usr/sbin:/usr/bin

                /sbin/depmod -a
                /sbin/modprobe ip_masq_irc ports=6667,6666,6665,1024
                /sbin/modprobe ip_masq_quake 26000,27000,27910,27960

                echo "1" > /proc/sys/net/ipv4/ip_forward
                echo "1" > /proc/sys/net/ipv4/ip_dynaddr

                # set ip addresses and interfaces
                extip="`/sbin/ifconfig eth1 | grep 'inet addr' | awk '{print
$2}' | sed 

You might want to echo extip to be sure your external ip address is being
resolved correctly.
What does the output of ipchains -L look like?

                's/.*://'`"
                extint="eth1"
                intint="eth0"
                intnet="192.168.0.0/24"

                # timeouts
                ipchains -M -S 7200 10 160

                # input
                ipchains -F input
                ipchains -P input REJECT

                # i just found the below line 2day and didnt notice a
difference?
                ipchains -A input -i $extint -s 0/0 67 -d 0/0 68 -p udp -j
ACCEPT

                ipchains -A input -i $intint -s $intnet -d 0.0.0.0/0 -j
ACCEPT
                ipchains -A input -i $extint -s $intnet -d 0.0.0.0/0 -j
REJECT
                ipchains -A input -i $extint -s 0.0.0.0/0 -d $extip/32 -j
ACCEPT
                ipchains -A input -i lo -s 0.0.0.0/0 -d 0.0.0.0/0 -j ACCEPT
                ipchains -A input -s 0.0.0.0/0 -d 0.0.0.0/0 -j REJECT

                # output
                ipchains -F output
                ipchains -P output REJECT

                ipchains -A output -i $intint -s 0.0.0.0/0 -d $intnet -j
ACCEPT
                ipchains -A output -i $extint -s 0.0.0.0/0 -d $intnet -l -j
REJECT

                # this one i dont even understand why it's supposed 2 reject
it, it looks 
                legit 2 me.  i got this from the howto.
                ipchains -A output -i $extint -s $intnet -d 0.0.0.0/0 -l -j
REJECT

                ipchains -A output -i $extint -s $extip/32 -d 0.0.0.0/0 -j
ACCEPT
                ipchains -A output -i lo -s 0.0.0.0/0 -d 0.0.0.0/0 -j ACCEPT
                ipchains -A output -s 0.0.0.0/0 -d 0.0.0.0/0 -l -j REJECT

                # forward
                ipchains -F forward
                ipchains -P forward DENY

                ipchains -A forward -i $extint -s $intnet -d 0.0.0.0/0 -j
MASQ
                ipchains -A forward -s 0.0.0.0/0 -d 0.0.0.0/0 -l -j REJECT

                # eof


                i'd imagine im missing something crutial in the rc.firewall.
                From what i can tell, the dcc chat sends a request, they get
the
                request, and send an acknowledgement (which im waiting for)
and I
                never get it.  I'm assuming that the ruleset is somehow
blocking it
                from coming back.  This problem seems to be very similiar to
what im
                experiencing with the games too.

Try logging the last REJECT rule in your input chain to be sure that it is
not falling off the end of the chain.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to