/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ I'm currently having a problem with masquerading UDP packets back and forth thru my linux box. I have a Redhat linux 6.0 system (kernel 2.2.5-15), I have to use this release/kernel because that's what the drivers I have for my network gear support (they are binaries, rather the source). I have an ABA2030 Satelite Reciever card (made by BoardLogic, also called the "Satelite Express+". All incoming traffic from my static IP comes in through this interface (aba_0) and all traffic goes out via my dial up circuit (ppp0). Everything seems to work fine with very few ipchaining rules (here's my rules at the moment). ipchains -M -S 7200 10 160 ipchains -P forward DENY ipchains -A forward -s 192.168.1.0/255.255.255.0 -j MASQ ipchains -A input -s 207.46.204.0/24 -d 0/0 9000:9013 -p 17 -j ACCEPT my local network is 192.168.1.* and the linux machines local IP is 192.168.1.1 The problem for me is hard to "define". TCP seems to work just fine, and outgoing UDP traffic also works fine. The problem is when UDP traffic comes back I don't think all of it is being forwarded back to the request machine on the network. In particular my friends like to play the game "Asherons Call" through the gateway, if I dialup with just the modem and avoid using the satelite return (By using a different dialup account) this game will operate fine. This game uses UDP, ports 9000 thru 9013 for IP addresses 207.46.204.* to send back UDP packets, here is exactly what it does: Connection AC IP address Port(s) Initial UDP Outbound 207.46.204.* 9000 Subsequent UDP Outbound 207.46.204.* 9004, 9008, 9012 Subsequent UDP Inbound 207.46.204.* 9000, 9001, 9004, 9005, 9008, 9009, 9012, 9013 and Connection AC IP address Port(s) Initial UDP Outbound 207.46.204.* 9004 Subsequent UDP Outbound 207.46.204.* 9000, 9008, 9012 Subsequent UDP Inbound 207.46.204.* 9000, 9001, 9004, 9005, 9008, 9009, 9012, 9013 Now when he trys to play the game while using the satelite return-path it will get have way though connecting, gets into the game and then fails to recieve some of the information. My guess (however I'm not at all certain) is that the subsequent UDP inbound ports 9001,9005,9009,90013 and maybe others aren't geting fed back properly (though how masquerading deals with UDP packets is still a bit of a mystery to me - could anyone point me to a good resouce for information on this, how does the masquerading box know how to funnel packets back to the original machine, when know connection is established.. Any help would be greatly recieved, if someone feels they have information not necessarily usefull to the mailing list just email me directly: [EMAIL PROTECTED] Thanks, - Alex _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
