/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Ian Chilton wrote:
> I am having a few problems with ipchains & IP Masq...sorry about the long
> message :)
>
> I seem to be getting a *log* of entries in my /var/log/sys.log and kern.log
> files..It's getting really annoying, because over a day, my log files are
> getting *big*
>
>
> Most of them are like this:
> (I have heard 224.0.0.1 is for Multicast....but should this be happening?
> Can I stop it?)
> (The 62.x.x.x is my dynamic IP address on ppp0 when I am connected)
>
> May 2 21:50:47 ichilton kernel: Packet log: input REJECT ppp0 PROTO=2
> 62.252.226.217:65535 224.0.0.1:65535 L=28 S=0x00 I=1 F=0x0000 T=1 (#35)
even though it's on the input chain, the source is your ip address
so some software on yuor host must be multicasting this packet and
it gets blocked on its way back in. find out what piece of software
is sending these packets. or just reconfigure your kernel to not
include support for multicasting. then see what software breaks :)
> I also get a *few* entries like this (194.168.x.100 is my ISP's DNS servers,
> which I am using in resolv.conf and on the windows machines):
> May 2 21:50:34 ichilton kernel: Packet log: output REJECT ppp0 PROTO=17
> 62.252.240.161:1039 194.168.8.100:53 L=67 S=0x00 I=20609 F=0x0000 T=64 (#65)
check your firewall rules. they must be wrong if you want to allow such
packets. i'd recommend not allowing client dns queries, though. it's
better to only use a dns server with "query-source port 53" so the
the source port (and hence the destination port of the reply packets)
is 53, not 1024:4999.
> There is also a *few* entries like this, which I don't know where the IP's
> are:
> May 2 19:55:10 ichilton kernel: Packet log: output REJECT ppp0 PROTO=6
> 62.252.238.38:61239 209.155.82.18:20 L=40 S=0x00 I=10163 F=0x4000 T=127
these all look like masqueraded hosts (source port in 61000:65096) trying
to passive ftp to the outside. do your ipchains rules allow masqueraded
clients to do passive ftp? it is odd, though. both command channel
connections (20) and data channel connections (21) are appearing,
so at some of the masqueraded hosts are getting as far as initiating
the command channel and then failing on the data channel.
> Also, another problem, possibly with ipchains or not...
>
> I ocasionally use webmin (http://www.webmin.com/webmin) to setup stuff like
> cron jobs...
>
> It is a configuration system utility which runs on port 10000, so you just
> point a browser to:
> http://machinename:10000 and you can configure all sorts :)
>
> However, when using on the network, I keep getting Page Can't be displayed,
> DNS Error coming up. When I click Refresh a few times, it finally loads the
> page..
>
> It seems to work OK sometimes, and not others..
>
> Could this be the firewall causing this?
yes. since the firewall is blocking traffic to at least some of your
dns servers (above) you should get dns problems occurring.
> And last question, connecting through IP Masq seems much slower than
> connecting a windows box direct on the same ISP. I have checked through some
> of the things mentioned in the IP Masq HOWTO, but can't find anything
> wrong...any ideas here?
dns again. whenever a firewall causes big slow downs, it's probably dns.
dns timeouts can be anything up to 75 seconds depending on how many dns
servers you have listed in /etc/resolv.conf.
> I have attatched my firewall script to this message (tar.gz'd). I would also
> apreciate it if someone could spare a few minutes to have a quick look
> through and see if you have any suggestions..
i think you forgot to attach it.
raf
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.