Re: ip masquerading

From: Daniel Asarnow (dasarnow_at_gmail.com)
Date: 11/17/04

  • Next message: H. S.: "route takes long time to give the table"
    Date: Tue, 16 Nov 2004 19:04:16 -0800
    To: Debian Users <debian-user@lists.debian.org>
    
    

    Thanks for the advice. It looks like I'll be at this for a while...if
    I can't make any headway with it, I'll ask for more help

    Thanks again,
    da

    On Tue, 16 Nov 2004 03:11:38 -0600, Yusuf <yusufad@myrealbox.com.delme> wrote:
    > Your firewall rules look, uh, ugly, meaning, not meant for human eyes.
    > You should try to isolate your problem from bottom to top:
    >
    > Try a minimalistic firewall. Just for testing, of course, as this is
    > totally insecure:
    >
    > # Clear all rules
    > /sbin/iptables -F; /sbin/iptables -t nat -F; /sbin/iptables -t mangle -F
    >
    > # Enable Masquerading
    > echo 1 > /proc/sys/net/ipv4/ip_forward
    > /sbin/iptables -t nat -A POSTROUTING -o ppp0 -j MASQUERADE
    >
    > If this solves your problems, then you should think about changing
    > firehol, making the firewall by hand (but with the great help of
    > fwbuilder), or (yuck!) trying to "debug" your current firehol rules.
    >
    > They are messing with the maximum segment size:
    >
    > YN tcpmss match 1400:1536 TCPMSS clamp to PMTU
    >
    > trying to divide oversized packets to the maximum transmission unit.
    > The MTU is traditionally a source of metaphysical and NAT troubles.
    >
    > The problem could also probably come from your connection settings. Try
    > different connections. You are over "fiver"? Try a dial-up for a change.
    >
    > DSL? Then maybee the aforementioned clamp is clashing with the one
    > provided by pppoe. Check the config in
    > /etc/ppp/providers/<your-config>. Watch for the syndrome of the Roaring
    > Penguin: a few weeks ago my router suddenly stopped NATing, the only
    > clue being an obscure cry in /var/log/messages:
    >
    > Sep 24 19:45:48 severo pppd[1770]: Couldn't increase MTU to 1500
    >
    > The dreaded MTU had again stroke! Well, more or less. The problem
    > resulted from the inclusion of the rp-pppoe.so plugin in my DSL config
    > after an update of pppoeconf. Or so I believe.
    >
    > Anyway, keep islolating the problem, using different frontends, configs,
    > connections, machines, religions, whatever, until you corner it in its
    > obscure burrow, and then, and then...!
    >
    > I have never recommended or performed a Linux reinstall becouse of
    > "soft" troubles (except that time when the filesystem went on vacation),
    > but there is always that option: partial or full reinstallation, quite
    > like in the ol' winbugs days. But much cleaner and quicker, of course.
    >
    > Good luck. You'll need it ;-)
    >
    > --
    >
    >
    > To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org
    > with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    >
    >

    -- 
    To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: H. S.: "route takes long time to give the table"

    Relevant Pages

    • Re: ip masquerading
      ... Your firewall rules look, uh, ugly, meaning, not meant for human eyes. ... resulted from the inclusion of the rp-pppoe.so plugin in my DSL config ... connections, machines, religions, whatever, until you corner it in its ... I have never recommended or performed a Linux reinstall becouse of ...
      (Debian-User)
    • Re: EPP Cost vs. Coupon Cost?
      ... Jay is right, don't get the, McAfee Security Center with ... VirusScan, Firewall, Spyware Removal, 15-months. ... i routinely buy the 1.83 for around $800 in your config. ... Network Card and Modem Integrated 10/100 Network Card and Modem ...
      (alt.sys.pc-clone.dell)
    • RE: Configure Firewall fails
      ... 39856232-Configure Firewall fails. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... <configuration, it completes all steps (Network Config, Secure Web Site ...
      (microsoft.public.windows.server.sbs)
    • RE: [fw-wiz] Cisco VPN Client "Stateful Firewall (Always On)"
      ... under network config in Windows 2000/NT. ... I have insisted that a firewall be included in this ... Basically, as I understand it, this feature allows all outbound ... connections while active, and all inbound connections originally established ...
      (Firewall-Wizards)
    • [VulnWatch] FVS318 Config stores usernames/passwds in plain text
      ... Netgear's FVS318 Firewall/VPN/Router stores Usernames and Passwords ... ProSafe VPN Firewall provides business-class protection at a NAT router ... The web interface includes a backup option to store your current config ...
      (VulnWatch)