This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.
------_=_NextPart_001_01C1E99B.E241FAC0
Content-Type: text/plain;
charset="iso-8859-1"
Hi Everyone,
Good day!
I really need your help. I am trying to portforward (say port 80)to another
network attached to our local network.
I used the two-interfaced template. It seems that the packets just got lost
somewhere.
Below is the diagram of the network.
+-----------+ +----+ +--------------+
| ISP''s Rtr +-----+ FW +-----+ LAN A |
+-----------+ +----+ |192.168.1.0/24|
+------+-------+
|
|
+------+------+
| Router A |
| 192.168.1.1 |
+------+------+
|
| T1 leased line
|
+-------------+
| Router B |
| 192.168.2.1 |
+------+------+
|
|
+------+-------+
| LAN B |
|192.168.2.0/24|
+------+-------+
|
+-------------+
| Server |
| 192.168.2.4 |
+-------------+
This one is taken from the rules (real ips are substituted):
ACCEPT net loc:$SERVER1 tcp $LOC_TCP_PORTS1 - 10.1.1.2
ACCEPT loc loc:$SERVER1 tcp $LOC_TCP_PORTS1 - 10.1.1.2
ACCEPT net loc:$SERVER1 udp $LOC_UDP_PORTS1 - all
Also the policy:
fw net ACCEPT
fw loc ACCEPT
net all DROP info
all all REJECT info
>From the params:
LOCAL_OPTIONS=routestopped,multi
LOCAL_NET=192.168.0.0/16
LOC_TCP_PORTS1=80
SERVER1=192.168.2.4
Here''s the routing table of the firewall (valid ip is substitured by
10.1.1.0):
Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt
Iface
10.1.1.0 * 255.0.0.0 U 40 0 0
eth0
192.168.1.0 * 255.255.255.0 U 40 0 0
eth1
192.168.2.0 * 255.255.255.0 U 40 0 0
eth1
127.0.0.0 * 255.0.0.0 U 40 0 0 lo
default 10.1.1.1 0.0.0.0 UG 40 0 0
eth0
On the server, I added a route to the LAN interface of the firewall.
I''m
not if I did was right. Am still new with networking also. Thanks in
advance.
Regards,
Rene
------_=_NextPart_001_01C1E99B.E241FAC0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html;
charset=3Diso-8859-1">
<META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version
5.5.2650.12">
<TITLE>Port Forwarding to another network</TITLE>
</HEAD>
<BODY>
<P><FONT SIZE=3D2 FACE=3D"Courier New">Hi
Everyone,</FONT>
</P>
<P><FONT SIZE=3D2 FACE=3D"Courier New">Good
day!</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New">I really need your
help. I am trying to portforward (say port 80)to another network
attached to our local network.</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New">I used the
two-interfaced template. It seems that the packets just got lost
somewhere.</FONT>
</P>
<P><FONT SIZE=3D2 FACE=3D"Courier New">Below is the
diagram of the network.</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">+-----------+
+----+ +--------------+</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New">| ISP''s
Rtr +-----+ FW +-----+ LAN
A
|</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">+-----------+
+----+ |192.168.1.0/24| </FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
+------+-------+</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
|</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
|</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
+------+------+</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
| Router A |</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
| 192.168.1.1 |</FONT>
<BR>
<FONT
SIZE=3D2 FACE=3D"Courier
New">
+------+------+
</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
|</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
| T1 leased
line
</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
|</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
+-------------+</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
| Router B |</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
| 192.168.2.1 |</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
+------+------+</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
|</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
|</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
+------+-------+</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
| LAN B
|</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
|192.168.2.0/24|</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
+------+-------+</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
|</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
+-------------+</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
| Server |</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
| 192.168.2.4 |</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">
+-------------+</FONT>
</P>
<P><FONT SIZE=3D2 FACE=3D"Courier New">This one is taken
from the rules (real ips are substituted):</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">ACCEPT
net
loc:$SERVER1 tcp
$LOC_TCP_PORTS1 - 10.1.1.2</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">ACCEPT
loc
loc:$SERVER1 tcp
$LOC_TCP_PORTS1 - 10.1.1.2</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">ACCEPT
net
loc:$SERVER1 udp
$LOC_UDP_PORTS1 -
all</FONT>
</P>
<BR>
<P><FONT SIZE=3D2 FACE=3D"Courier New">Also the
policy:</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">fw
net
ACCEPT
</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">fw
loc
ACCEPT
</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">net
all
DROP
info </FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">all
all
REJECT
info </FONT>
</P>
<BR>
<P><FONT SIZE=3D2 FACE=3D"Courier New">From the
params:</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">LOCAL_OPTIONS=3Droutestopped,multi </FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">LOCAL_NET=3D192.168.0.0/16</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">LOC_TCP_PORTS1=3D80</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">SERVER1=3D192.168.2.4</FONT>
</P>
<P><FONT SIZE=3D2 FACE=3D"Courier New">Here''s the
routing table of the firewall (valid ip is substitured by
10.1.1.0):</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New">Kernel IP routing
table
</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">Destination
Gateway
Genmask
Flags MSS Window irtt Iface </FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">10.1.1.0
*
255.0.0.0
U 40
0
0 eth0 </FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">192.168.1.0
*
255.255.255.0
U 40
0
0 eth1 </FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">192.168.2.0
*
255.255.255.0
U 40
0
0 eth1 </FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">127.0.0.0
*
255.0.0.0
U 40
0
0 lo </FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier
New">default
10.1.1.1
0.0.0.0
UG 40
0
0 eth0</FONT>
</P>
<P><FONT SIZE=3D2 FACE=3D"Courier New">On the server, I
added a route to the LAN interface of the firewall. I''m not
if I did was right. Am still new with networking also. Thanks in
advance.</FONT></P>
<BR>
<P><FONT SIZE=3D2 FACE=3D"Courier
New">Regards,</FONT>
<BR><FONT SIZE=3D2 FACE=3D"Courier New">Rene</FONT>
</P>
</BODY>
</HTML>
------_=_NextPart_001_01C1E99B.E241FAC0--