Displaying 20 results from an estimated 20000 matches similar to: "DNAT SSL?"
2003 Nov 11
2
NEWBIE: DNAT Prob
Hi gang,
I''ve got a problem with shorewall, it keeps dropping packets when it
should be DNATing them.
I want all connections on a tcp port 4662 to be forwarded to a machine
on my network (192.168.0.5) - the port is used for mldonkey (P2P app).
It seems to be partially working - loads of packets are being DNAT''ed
but some are not - I cant figure out why!
The firewall
2004 Dec 22
15
OpenVPN and DNAT
Hello Tom and all,
Quick question: Is it possible to operate an OpenVPN server from behind
a firewall?
Is it as simple as setting it up and placing:
DNAT net loc:192.168.10.20 udp 5000 - ipaddress
--
Paul Slinski -o)
Network Administrator /\
Global IQX, Inc. _\_v
Global IQX is the leader in integrated e-business automation solutions
for the group life and health insurance
2007 Nov 21
9
Trouble with DNAT After Upgrade
I''ve upgraded a 3-interface system from 2.0.8 to 3.2.6 on Debian, and I''m not
able to make DNAT work anymore. If someone could offer a suggestion of where
to look to fix this, it would be very much appreciated.
Problem Summary:
If I set DETECT_DNAT_IPADDRS=Yes, then I can''t access anything on my DMZ via
DNAT.
If I set DETECT_DNAT_IPADDRS=No, then **EVERYTHING**
2007 Nov 21
9
Trouble with DNAT After Upgrade
I''ve upgraded a 3-interface system from 2.0.8 to 3.2.6 on Debian, and I''m not
able to make DNAT work anymore. If someone could offer a suggestion of where
to look to fix this, it would be very much appreciated.
Problem Summary:
If I set DETECT_DNAT_IPADDRS=Yes, then I can''t access anything on my DMZ via
DNAT.
If I set DETECT_DNAT_IPADDRS=No, then **EVERYTHING**
2004 Oct 09
2
odd problem with proxyarp and DNAT
I have some hosts in a DMZ zone with proxyarp. In my local zone I have a host to which I DNAT.
I have discovered that I can reach the host in the local zone by attempting to connect to the fw (As expected) or ANY proxyarped host in my dmz zone (as not expected). Is this normal ?
(I''ve just discovered that actually the dnated host answers to requests sent to any IP routed to my host!)
2005 Apr 03
6
v1.2/DNAT
Some probably wish v1.2.12-2 out of Debian Woody would just go away, but it''s
what I''m using and really don''t wish to upgrade at this time (but will
eventually). My needs are rather simple and I''m sure it can handle the job.
I''ve read and re-read the FAQs and searched extensively for docs on what my
problem might be, but just cannot put my finger
2003 Oct 29
11
Shorewall prerouting to a manual proxy
Hallo,
I got a problem (I think it''s not a Problem, I am just to stupid to manage
it)
Iwant my Server (eth1: addr:10.0.123.1, Local Zone), eth0 is connectet to
the Student-Network (addr:172.16.129.106 Mask:255.255.248.0 gateway:
172.16.128.1, Net Zone), to forward all packages from port 80 on local
Zone to www-cache.uni-halle.de:3128 (172.16.128.1:3128) because I have to
use this
2006 Mar 13
1
Dynamic Zones and IPSET (with a DNAT for good measure!)
Hello all,
I have been putting together a shorewall firewall together for a couple
of days, but have hit a bit of a dead end.
I am using Shorewall 3.0.5
Shorewall has detected the following iptables/netfilter capabilities:
NAT: Available
Packet Mangling: Available
Multi-port Match: Available
Extended Multi-port Match: Available
Connection Tracking Match: Available
Packet Type
2004 Jun 05
5
DNAT or SNAT or both?
I have an internal (10.16.0.0/24) network which is routed out
via a proxy on port 80 only, this proxy is then routed to an
upstream proxy on port 8080, this then runs through a cluster
of caching (squid) proxies and then finally, goes out to the internet.
As there are a cluster of squid proxies, the IP of an internet-request
from the internal LAN is never the same, it changes to match the proxy
2008 Jan 17
16
Local network rejecting traffic
Hello!
I have this situation / interfaces:
Dsl0 - internet interface
Eth0 - local network
I have linux box with shorewall 2.2. And on the local network I also have a
hardware router. I have connected WAN port with settings of my linux box and
then created one more local network behind hardware router. It works fine.
I then wanted to use VPN function of this hardware router, so i created
2004 Sep 16
4
DNAT works, yet extremely slow
Hello all
I wanted to forward all incoming requests in port 80 to a server in my LAN,
and by using DNAT lines, it actually works. However, it is unstable, in the
sense that in the beggining of each connection (one or two seconds) it is
extremely fast, then it sometimes pauses and waits 30 seconds or so, then it
starts again and so on.
The line i used is :
DNAT net loc:192.168.0.210 tcp 80
DNAT
2005 Jan 07
8
Problem with bridging/routing on three interfaces and DNAT
Hello all,
I have a problem with external access to a postfix mailserver running on my
firewall as a mail-gateway. My setup with shorewall 2.2.0 rc4 is as follows:
eth0 is zone isf - this is an intranet to other companies
eth1 is zone loc - local network
eth2 is zone net - internet, fix ip adress
eth0 and eth1 are bridged
shorewall version
2.2.0-RC4
ip addr show
1: lo: <LOOPBACK,UP> mtu
2004 Apr 01
5
DNAT PPTP questions
I have two/three PPTP servers on my network and each one of them are on
their own subnet and I want to be able to send traffic to each and
everyone.
My rules file entry is as follows
DNAT net loc:1.1.1.1 tcp 1723
DNAT net loc:1.1.1.1 47
and
DNAT net loc:2.2.2.2 tcp 1723
DNAT net loc:2.2.2.2 47
however all the traffic only goes to 1.1.1.1 because its the first
DNAT entry.
I tried the
2005 Apr 01
3
DNAT question
If I want to use DNAT to forward data destined for a port on the firewall to a different port on a
machine behind the firewall, is this this syntax correct?
DNAT net:3599 loc:192.168.0.10 tcp 22
I can find bits at each end in the docs but not both ends.
TIA
richard
2006 Feb 07
7
Masquerading issue
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hello,
Shorewall-3.0.3
RH9 (+legacy updates)
eth0: loc: 192.168.1.0/24
eth0:0: loc: 192.168.20.0/24
eth1:: 69.70.32.8/29
I''m worked all day on an issue I found today and I just can''t find a way
to fix my problem.
So, basically, for now, my network looks like this:
Internet
^
|
(69.70.32.8/29)
Firewall
192.168.1.1
2006 Aug 18
3
DNAT Security Hole?
# shorewall version
3.2.1
SNAT is enabled. Setting up DNAT to do port forwarding -- this example
looked exactly like what I wanted:
(FAQ 1c) From the internet, I want to connect to port 1022 on my firewall
and have the firewall forward the connection to port 22 on local system
192.168.1.3. How do I do that?
In /etc/shorewall/rules:
#ACTION SOURCE DEST PROTO DEST PORT
2004 Sep 02
5
DNAT and ping
I have the following
interfaces
loc eth0
net0 eth1
net1 eth2
(net0 and net1 are the two ISP networks)
policy
loc net0 ACCEPT
loc net1 ACCEPT
net0 all DROP info
proxyarp
209.189.103.204 eth0 eth1 no no
params
Pellucidar=192.168.124.232
rules
DNAT net0 loc:$Pellucidar tcp 22,80,1950,50005 - 209.189.103.204
ACCEPT all all icmp
2005 Feb 15
5
dnat problem
Hi, im running shorewall 2.0.16 with centos 3 (iptables v1.2.8), everything
is working fine for several days, i have configured a masq lan and all the
outgoing traffic is ok, but now i want to redirect (port forward) the
external web traffic to an internal machine, somethig like this
INTERNET ---------> SHOREWALL -------------------> INTERNAL_MACHINE
[public
2004 Jan 21
3
FW: DNAT and masq problem with kernel 2.4.23
Hi,
after kernel upgrade to 2.4.23 my existing configuration of shorewal 1.4.8
will not start / it fail on DNAT and/or masq with message: "iptables:
Invalid argument" /
I founded some similar problems description - see links bellow, but there is
no solution how to get work shorewall with DNAT and masq with 2.4.23 kernel.
http://www.ussg.iu.edu/hypermail/linux/kernel/0312.0/0268.html
2004 Aug 30
4
DNAT and PPTP
Hello,
I''m trying to setup DNAT to forward to a PPTP Server behind Shorewall. I setup the PPTP rules per your documentation with tcp port 1723 and Protocol 47 DNAT to my PPTP Server in the local zone. Looking at the logs it is dropping the connection going to port 1723. It is also dropping UDP port 1701, don''t know if it is of any significance. I looked at FAQ 1a and b and the