/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Vander Francisco wrote:

>  I'm trying this for more than month...
> 
>  Sombody help me, please...
> 
>  I want access a server win2000(192.198.192.5)  that is inside my net whit
>  Port Foward uzing port 8000
> 
>  In another word, I want do http://Extern_Add:8000 and access
>  http://192.198.192.5 which is intern..
> 
>  I know you guys know that very well..
> 
>  I'm using Red Hat 6.1, and i reformated the HD and instaled everything
>  again, but still don't working,
> 
>  This is my rules..
> 
> #!/bin/sh
> # rc.firewall script
> # *********************** Route Section  **********************
> # ************************** Modules **************************
> 
> /sbin/depmod -a
> /sbin/modprobe ip_masq_mfw
> /sbin/modprobe ip_masq_portfw
> /sbin/modprobe ip_masq_ftp
> /sbin/modprobe ip_masq_raudio
> /sbin/modprobe ip_masq_cuseeme
> /sbin/modprobe ip_masq_vdolive
> 
> # ************************ Rules *****************************
> 
> echo "1" > /proc/sys/net/ipv4/ip_forward
> ipchains -F
> ipchains -M -S 7200 10 60
> ipchains -P forward DENY
> ipchains -A forward -s 192.168.192.0/24 -j MASQ -v
> ipmasqadm portfw -f
> ipmasqadm portfw -a -P tcp -L Extern_Add 8000 -R 192.168.192.5 80
> ipmasqadm portfw -l
> 
> # ***********************************************************
> 
>  Here is the result of my rule...
> 
> MASQ  all opt    ------ tos 0xFF 0x00  via *    192.168.192.0/24 ->
> 0.0.0.0/0    n/a
> prot localaddr            rediraddr               lport    rport  pcnt  pref
> TCP  Extern_Add  land.net.com             8000      www    10    10
> 
>  __________________________________________________________________
> 
>  Here is the result of TCPDUMP when I try access the http://Extern_Add:8000
> 
>  In that case I try access from the machine 192.168.192.4 that is inside my
>  net, but when I try from outside, I have the same results...
> 
> 13:19:49.436674 eth1 < 192.168.192.4.1488 > Extern_Add.8000: S
> 269351476:269351476(0) win 8192 <mss 1460,nop,nop,sackOK> (DF)
> 13:19:49.436770 eth1 > 192.168.192.1 > 192.168.192.4: icmp: redirect
> 192.168.192.5 to host 192.168.192.5 [tos 0xc0]
> 13:19:49.436831 eth1 > 192.168.192.4.1488 > 192.168.192.5.www: S
> 269351476:269351476(0) win 8192 <mss 1460,nop,nop,sackOK> (DF)
> 13:19:52.350264 eth1 < 192.168.192.4.1488 > Extern_Add.8000: S
> 269351476:269351476(0) win 8192 <mss 1460,nop,nop,sackOK> (DF)
> 13:19:52.350303 eth1 > 192.168.192.1 > 192.168.192.4: icmp: redirect
> 192.168.192.5 to host 192.168.192.5 [tos 0xc0]
> 13:19:52.350358 eth1 > 192.168.192.4.1488 > 192.168.192.5.www: S
> 269351476:269351476(0) win 8192 <mss 1460,nop,nop,sackOK> (DF)
> 
>  __________________________________________________________________

your script looks fine but it can't work from inside the masqueraded
network without michael best's masq-demasq patch. port forwarding
ordinarily only works from the outside for the reason you can see
in the tcpdump output: packets destined for the external address
leave the network via the default route (which won't work) so an icmp
redirect message is generated to inform the originating host that it's
doing the wrong thing.

you say it doesn't work from the outside either (it looks like it should).
what's tcpdump output look like when you try it from the outside?

raf

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to