Displaying 20 results from an estimated 50000 matches similar to: "Adding/Dropping DNAT rules dynamically"
2005 May 27
3
Requesting help with a log entry
Does anyone know what this log entry indicates? What service running on a
WinNT server would send out a UDP packet with source port 137 and
destination port 1? (I was unable to get any clarity from Google...)
---------
May 27 11:01:47 ykrgw kernel: Shorewall:loc2net:DROP:IN=eth0 OUT=eth1
SRC=192.168.3.3 DST=166.84.151.198 LEN=84 TOS=0x00 PREC=0x00 TTL=127
ID=37008 PROTO=UDP SPT=137 DPT=1
2004 Aug 31
1
rules & nat files for DNAT
Dear experts,
Quick quotation...
I have a sendmail server behind the shorewall-2.1.7 server. I would like
to do Port forwarding (DNAT) for clients on the internet, who need to
access the mail server.
Please let me know, which way is the most suitable to accomplish this;
using following 2 types of configurations
Setup -
Internet -- > shorewall -- > sendmail
2005 Feb 10
1
DNAT Entry In Rules Isn''t Working...
So I finally got shorewall up with my linux box, which pipes out to a
switch, and then my machines...
Problem now is on my one machine, I have a remote admin server running on
port 4899... So since I''m using masq, I added a DNAT entry in my rules
instead of an ACCEPT
DNAT net loc:192.168.1.3 tcp 4899
So when I try to access my remote admin using my external IP, even from
inside, I
2004 Aug 26
1
DNAT IP-Adding
Hello List.
I''m new here,
and am staring off with a pretty common question, i think.
I want to have my router DNAT incomeing connections for other IP''s than it''s
WAN IP.
In my other setup, just adding that IP as Destination Address was enough.
But that was a bit older Version of Shorwall.
In my new Setup, Shorewall 2.0.7 Debian Sarge, i have this line:
DNAT
2005 Jun 22
0
Issue migrating from 1.4.6c to 2.4.0 with all zone in DNAT rule
Hi all,
net : internet zone
dmz : DMZ zone
Lan : local network zone
in 1.4.6c this rule :
DNAT all lan:10.0.0.1 tcp http - 192.0.0.1
does generate the following iptables rules in nat table :
Chain OUTPOUT
DNAT tcp -- 0.0.0.0/0 192.0.0.1 tcp dpt:http to:10.0.0.1
Chain net_dnat
DNAT tcp -- 0.0.0.0/0 192.0.0.1 tcp dpt:http to:10.0.0.1
Chain dmz_dnat
2003 Nov 11
2
NEWBIE: DNAT Prob
Hi gang,
I''ve got a problem with shorewall, it keeps dropping packets when it
should be DNATing them.
I want all connections on a tcp port 4662 to be forwarded to a machine
on my network (192.168.0.5) - the port is used for mldonkey (P2P app).
It seems to be partially working - loads of packets are being DNAT''ed
but some are not - I cant figure out why!
The firewall
2004 Aug 30
4
DNAT and PPTP
Hello,
I''m trying to setup DNAT to forward to a PPTP Server behind Shorewall. I setup the PPTP rules per your documentation with tcp port 1723 and Protocol 47 DNAT to my PPTP Server in the local zone. Looking at the logs it is dropping the connection going to port 1723. It is also dropping UDP port 1701, don''t know if it is of any significance. I looked at FAQ 1a and b and the
2011 Mar 17
2
DNAT problem
Hi All,
I use rather old Shorewall 3.2.6 and I know it''s no longer supported.
I haven''t been updating the software because it works as intended until now.
The problem is a simple DNAT rule. I actually have around 8 DNAT rules
and they all work just fine.
Here is what I want to achieve. I have a SMTP server in my LAN (lets say
address 192.168.1.10). The SMTP daemon listens on
2004 Sep 07
1
Problem with DNAT 3 IP''s two NIC
Thanks Tom
Sorry, I was wrong, this is the correct question...
I have this configuration:
|
Email Server 192.168.0.253 |
___|___ Port 25 SMTP ___|____ ____
| LAN |-------------------------------------Eth1
2005 Mar 02
3
duplicated dnat entries
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hello all,
im using shorewall 2.2.1 on a CentOS 4, im newbie with shorewall,
just testing it
i created a dnat rule like this
#ACTION SOURCE DEST PROTO DEST
SOURCE ORIGINAL RATE USER/
# PORT
PORT(S) DEST LIMIT
2005 Dec 14
2
DNAT config not working
I am having a problem that I really just don''t get....
I have this in my rules file:
DNAT net loc:192.168.1.2 tcp 21 21
Everything worked fine earlier today.. Now it is dropping packets destined
for Port 21
/var/log/messages:
Dec 14 00:36:39 pcp08479598pcs kernel: Shorewall:net2all:DROP:IN=eth0 OUT=
MAC=00:0b:6a:3f:e6:72:00:01:5c:22:92:42:08:00 SRC=24.210.36.92
DST=68.57.216.61
2006 Mar 13
1
Dynamic Zones and IPSET (with a DNAT for good measure!)
Hello all,
I have been putting together a shorewall firewall together for a couple
of days, but have hit a bit of a dead end.
I am using Shorewall 3.0.5
Shorewall has detected the following iptables/netfilter capabilities:
NAT: Available
Packet Mangling: Available
Multi-port Match: Available
Extended Multi-port Match: Available
Connection Tracking Match: Available
Packet Type
2004 Oct 09
2
odd problem with proxyarp and DNAT
I have some hosts in a DMZ zone with proxyarp. In my local zone I have a host to which I DNAT.
I have discovered that I can reach the host in the local zone by attempting to connect to the fw (As expected) or ANY proxyarped host in my dmz zone (as not expected). Is this normal ?
(I''ve just discovered that actually the dnated host answers to requests sent to any IP routed to my host!)
2004 Oct 17
1
DNAT not working anymore
Heya guys and gals,
I had a shorewall 1.4.x running on my router and somehow it decided to
stop working.
I didn''t really change something, it just stopped working really.
Anyway, here the info that is asked for on the support page at first:
# shorewall version
2.0.9
# ip addr show
1: lo: <LOOPBACK,UP> mtu 16436 qdisc noqueue
link/loopback 00:00:00:00:00:00 brd
2004 Sep 02
3
Fwd: Bug#268999: shorewall: Allow action templates to use DNAT target
Hi all in the ShoreWall community,
[please CC me since I''m not on the list]
I had been using FIAIF for a little while, and the setup of ShoreWall
has been much easier, the config for each operation in one place, and
I''m very happy with it.
That said, it looks like one of the concepts could be taken a bit
further. In this case, it is actions.
To get the process started, I
2004 Jan 21
3
FW: DNAT and masq problem with kernel 2.4.23
Hi,
after kernel upgrade to 2.4.23 my existing configuration of shorewal 1.4.8
will not start / it fail on DNAT and/or masq with message: "iptables:
Invalid argument" /
I founded some similar problems description - see links bellow, but there is
no solution how to get work shorewall with DNAT and masq with 2.4.23 kernel.
http://www.ussg.iu.edu/hypermail/linux/kernel/0312.0/0268.html
2004 Sep 22
3
Strange DNAT problems with shorewall 1.4.8
I''ve had some issues with my network, and I''ve had to reconfigure my
Gibraltar CD. It runs shorewall 1.4.8, and I have a 2-interface setup, so
I downloaded the relevant files from the install page.
Masq and such works, but I''m having a problem with my port forwarding. It
works for port 22, but it doesn''t seem to work for any other port.
I''ve turned
2005 Apr 27
1
Problems with DNAT
Hi, i''m a shorewall users and i have the following problem:
I have one class C range of IP''s and i have three zones (net, dmz , loc)
I need create one rule to dnat one valid ip address (but not in use in
one computer) to one invalid host in my loc zone.
How i do?
I try this:
DNAT net:200.200.200.200 dmz:200.193.137.38 tcp
137,138,139,445 -
2004 Sep 07
1
Problem with DNAT
Hi
I have this configuration:
eth0 Link encap:Ethernet HWaddr 00:C0:F0:54:DC:1E
inet addr:10.10.10.166 Bcast:10.10.10.167 Mask:255.255.255.248
inet6 addr: fe80::2c0:f0ff:fe54:dc1e/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1738708 errors:0 dropped:0 overruns:0 frame:0
TX packets:1538724 errors:0 dropped:0
2008 Jan 20
2
DNAT net to net (shorewall 3.2.6)
Hello,
On my systems i use shorewall 3.2.6.
Now all systems where replace by new ones with new ip''s.
So i tried with DNAT to map the old ip''s to the new one as long as DNS is
updated.
But i didn''t get it work.
I see in tcpdump that a connect from client-ip to new-server-ip is done
while connection the old on.
But i get no response.
Did i configure something in the