Displaying 20 results from an estimated 11000 matches similar to: "DNAT PPTP questions"
2004 Aug 30
4
DNAT and PPTP
Hello,
I''m trying to setup DNAT to forward to a PPTP Server behind Shorewall. I setup the PPTP rules per your documentation with tcp port 1723 and Protocol 47 DNAT to my PPTP Server in the local zone. Looking at the logs it is dropping the connection going to port 1723. It is also dropping UDP port 1701, don''t know if it is of any significance. I looked at FAQ 1a and b and the
2008 Sep 05
5
PPTP Client Behind a Shorewall Firewall
Hi all, I´m running a server that frecuently needs to open a pptp
session with a remote server outside my Company. This server is running
behind a Shorewall firewall and I don´t find information in Shorewall
web page because there is no information in the link
http://www.shorewall.net/PPTP.htm#ClientsBehind
Nowadays I can connect this server with the remote one but te session is
closed after
2004 Apr 14
1
PPTP Server running behind Shorewall
Hi friends, I need help.
I''ve PPTP Server running behind Shorewall. The PPTP server is working OK in my
LAN, but I want to connect outside and It isn''t working.
I''ve configurate shorewall like http://www.shorewall.net/PPTP.htm.
I add only this lines in my rules
DNAT net loc:165.182.15.15 tcp 1723 - IPext
DNAT net loc:165.182.15.15 47 - - IPext
It isn''t
2007 Jun 05
9
PPTP port forwarding question
Hello,
Please see the following picture:
http://www.wilson-kwok.com/pptp.jpg
I used one to one NAT from 210.0.0.1 to 192.168.0.2 for web server,
and then use port forwarding from 210.0.0.1 to 192.168.0.3 for pptp server,
but I cannot connect from my home to pptp server.
Here is the nat file:
210.0.0.1 eth0:2 192.168.0.2
Here is the rules
2004 Sep 30
2
2 DSL link, DNAT & SNAT
Sorry for the long descritpion of the problem, I''d like to know If I
misunderstand something or if I meet an intrinsic limit of my setup.
217.58.51.162 HDSL eth1 - SRV_XP: 192.168.254.10
eth0: 192.168.254.1 -----+------------------+-------
81.121.243.250 ADSL eth3 -
I want to allow incoming pptp request (port 1723) to be forwarded to
srv_xp
2004 Sep 23
9
help with a W2K VPN client 619 error and PPTP server
I''ve got what I think is a fairly simple home network configuration with one
Linux box functioning as the firewall, VPN server, DHCP server and
file/print server. I am having trouble configuring both a VPN server
(PopTop) and the firewall rules for a W2K PPTP VPN client. The VPN server
runs on the firewall machine and the VPN client runs on a W2K machine behind
the firewall. The VPN
2005 Jan 20
1
Can I pass PPTP packets thru 2 firewalls?
Is it possible to pass PPTP packets through 2 firewalls before
they hit the remote access server?
I installed a Netgear ProSafe VPN firewall as the first line of
defense in my network. I have since set up a Fedora Core 2 server
running Shorewall 2.1.3 and Squid in
non-transparent mode, between the Netgear unit and my network.
So, the Netgear faces the Internet with a public, static, IP address.
2006 Nov 30
14
My macro is flawed?
Hi all,
I have a VPN setup but it only works once in a while. It seems my firewall
(shorewall 3.0.8) is blocking protocol 47.
Here is what I have:
eth0: internet
eth2: dmz - my pptp server
My entry In the rules file:
pptp/ACCEPT fw dmz:192.168.253.2
My pptp macro
###############################################################################
#ACTION SOURCE
2005 Jan 03
8
load balancing and DNAT
Does anyone know if load balancing and DNAT work well together? I know
that load balancing and NAT do not, but what about a simple port forward?
I can''t apply Julian Anastasov''s patches, because they don''t work with
PPTP patches. :/
Anyhow, a simple:
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport xxx -j DNAT --to
yyy:xxx
iptables -I FORWARD -i eth0 -d yyy -p
2003 Feb 24
5
Bug in Shorewall check?
I made a boo boo in my config and put in this rule
#PPTP
DNAT net:213.67.241.162/217.209.46.204/32
loc:192.168.221.200 tcp 1723
DNAT net:213.67.241.162/32,217.209.46.204/32
loc:192.168.221.200 47 -
And the the following happened.. and I wonder why it didn''t complain? I
am sure I am just misunderstanding some doc
2003 Jan 30
4
ACCEPT vs DNAT
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi all,
Can someone refresh my memory on the difference between the following
(where dmz contains an RFC 1918 address host)?
ACCEPT net dmz tcp 80 - all
DNAT net dmz tcp 80
I''m trying to generate a script for maintaining multiple interconnected
firewalls from shared policy, rules, and zone files, and i
2004 Oct 04
6
Appreciate help with Shorewall and VPN
Hello all,
I had setup shorewall before succesfully with a normal LAN to internet
connection. Now I''m connected to the internet via VPN and I got problems
with configuring Shorewall. Any help is appreciated.
This is my setup:
- Gentoo Linux laptop (kernel gentoo-dev-sources-2.6.8.1) with Shorewall
2.0.4 (setup for Standalone one interface) and iptables 1.2.11
- VPN client is
2005 Mar 08
3
question about vpn
on i have a small question we have a linux box with a windows 2003
server well we natted all the ports and mail is working
remote desktop is working web is working the only thing that does not
work is vpn how can i foward vpn traffic to this server i checked the
site and searched for foward vpn and got nothen can somone please
enlight me where to start
Marshal McInnis Tech / Web
2003 Jan 22
5
Proxy arp and pptp
Hi all!
I''ve set up a Linux box with shorewall doing proxy arp as per http://www.shorewall.net/shorewall_setup_guide.htm#ProxyARP the 5.2 (non routed) example. Everything is working great except for one thing, and that leads me to my question: is there a conflict between proxy arp and pptp? I''ve set the apropriate ACCEPT rules to allow tcp port 1723 and protocol 47 to the host
2006 Nov 21
7
VPN Solution
Greetings List Members,
I''ll firstly apologise if this isn''t the place that I should be posting this
message but here goes.
What I want to do is have a VPN (PPTP/IPSEC/CIPE/etc) server, but it must
support more than one simultaneous connection.
I currently have a PPTP VPN server setup that has port 1723 and protocol 47
DNAT''d through to the internal IP
2004 Sep 10
1
Is ProxyARP or NAT entries really neccesary for DNAT to work?
I have been trying to get DNAT to work and I actually have succeeded
too, however, not how I thought it would work when reading through the
documentation.
1. No matter what I do I cannot get DNAT to work unless I have an entry
in eiter the nat or the proxyarp file. Is that really how it''s supposed
to be? I can''t find anything about it in the documentation.
2. Also, in the
2004 Jan 21
3
FW: DNAT and masq problem with kernel 2.4.23
Hi,
after kernel upgrade to 2.4.23 my existing configuration of shorewal 1.4.8
will not start / it fail on DNAT and/or masq with message: "iptables:
Invalid argument" /
I founded some similar problems description - see links bellow, but there is
no solution how to get work shorewall with DNAT and masq with 2.4.23 kernel.
http://www.ussg.iu.edu/hypermail/linux/kernel/0312.0/0268.html
2005 Jan 25
2
DNS, DNAT and Notifies
I have a pretty straightforward shorewall (v 2.0.12) setup in my Phoenix
office.
IP addresses on the firewall
eth0 172.16.10.249
eth1 12.47.198.100
eth1:1 12.47.198.108
eth1:2 12.47.198.101
eth2 172.16.11.249
interfaces:
loc eth0 detect
net eth1 detect blacklist
dmz eth2 detect
vpn1 tun1 192.168.124.255
zones
net Net
2004 Oct 09
2
odd problem with proxyarp and DNAT
I have some hosts in a DMZ zone with proxyarp. In my local zone I have a host to which I DNAT.
I have discovered that I can reach the host in the local zone by attempting to connect to the fw (As expected) or ANY proxyarped host in my dmz zone (as not expected). Is this normal ?
(I''ve just discovered that actually the dnated host answers to requests sent to any IP routed to my host!)
2004 Sep 02
3
Fwd: Bug#268999: shorewall: Allow action templates to use DNAT target
Hi all in the ShoreWall community,
[please CC me since I''m not on the list]
I had been using FIAIF for a little while, and the setup of ShoreWall
has been much easier, the config for each operation in one place, and
I''m very happy with it.
That said, it looks like one of the concepts could be taken a bit
further. In this case, it is actions.
To get the process started, I