[aclug-L] IP Forwarding
[Top] [All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index] [Thread Index]
Im attempting to use a Linux (Caldera OpenLinux) box as a firewall which
forwards IP packets from one network to another. I have two working
network cards installed in the server and have recompiled, according to
the Linux howto pages, the kernel to include the necessary features for IP
forwarding/masquerading. Both sides of the firewall can ping the IP
number of the network card which is directly attached, but, neither side
can ping the IP numbers on the other network. My configuration is as
follows:
[root@bilbo glen]# ifconfig
lo Link encap:Local Loopback
inet addr:127.0.0.1 Bcast:127.255.255.255 Mask:255.0.0.0
UP BROADCAST LOOPBACK RUNNING MTU:3584 Metric:1
RX packets:61 errors:0 dropped:0 overruns:0
TX packets:61 errors:0 dropped:0 overruns:0
eth0 Link encap:Ethernet HWaddr 00:A0:C9:71:53:FF
inet addr:198.248.166.17 Bcast:198.248.166.255
Mask:255.255.255.0
IPX/Ethernet 802.2 addr:00A0C97153FF
IPX/Ethernet 802.3 addr:00000501:00A0C97153FF
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:171530 errors:0 dropped:0 overruns:0
TX packets:7248 errors:0 dropped:0 overruns:0
Interrupt:5 Base address:0xe400
eth1 Link encap:Ethernet HWaddr 00:A0:C9:71:53:FE
inet addr:192.168.2.1 Bcast:192.168.2.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:202 errors:0 dropped:0 overruns:0
TX packets:119 errors:0 dropped:0 overruns:1
Interrupt:9 Base address:0xe800
[root@bilbo glen]# route -n
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use
Iface
255.255.255.255 0.0.0.0 255.255.255.255 UH 0 0 0
eth0
198.248.166.0 0.0.0.0 255.255.255.0 U 0 0 21
eth0
192.168.2.0 0.0.0.0 255.255.255.0 U 0 0 3
eth1
127.0.0.0 0.0.0.0 255.0.0.0 U 0 0 5 lo
0.0.0.0 198.248.166.254 0.0.0.0 UG 1 0 5
eth0
[root@bilbo glen]#
The ipfwadm commands I've used are those given in the IP Masquerading
howto page.
ipfwadm -F -p deny
ipfwadm -F -a m -S 192.168.1.0/24 -D 0.0.0.0/0
Any suggestions on why this doesn't work or how I can diagnose the
problem?
Glen Diener
Tabor College
glen@xxxxxxxxxxxxxxxx
---
This is the Air Capitol Linux Users Group discussion list. If you
want to unsubscribe, send the word "unsubscribe" to
aclug-L-request@xxxxxxxxxxxx. If you want to post to the list, send your
message to aclug-L@xxxxxxxxxxxx.
- [aclug-L] IP Forwarding,
Glen Diener <=
|
|