[SLE] SuSEfirewall2 and games

From: Keith Mickunas (keith_at_mickunas.net)
Date: 07/27/03

  • Next message: Jim Norton: "Re: [SLE] Forcing 3Ware ATA module on IRQ 10"
    Date: Sun, 27 Jul 2003 16:28:58 -0500
    To: suse-linux-e@suse.com
    
    

    I'm really sorry if this is covered all the time, but I just can't figure it
    out. Is there a simple way to set up the firewall to allow windows machines to
    play games on the internet? I've been through the manuals, the conf file,
    unofficial faq, and I'm not having a lot of luck.

    This is what I have set up:
    P2 running SuSE 8.2 Pro with all the latest updates
    eth0 connected to the internet
    eth1, 192.168.0.201, connected to the internal network
    Internal machines can access the web, external machines can access ssh and the
    webserver on the SuSE machine.

    The game I want to play is using port 2325, and some others show up for source
    ports. Are these the correct settings?

    FW_QUICKMODE="no"
    FW_DEV_EXT="eth0"
    FW_DEV_INT="eth1"
    FW_DEV_DMZ=""
    FW_ROUTE="yes"
    FW_MASQUERADE="yes"
    FW_MASQ_DEV="$FW_DEV_EXT"
    FW_MASQ_NETS="0/0" - shouldn't this masquerade every port?
    FW_PROTECT_FROM_INTERNAL="no"
    FW_AUTOPROTECT_SERVICES="yes"
    FW_SERVICES_EXT_TCP="http https ssh "
    FW_SERVICES_EXT_UDP=""
    FW_SERVICES_EXT_IP=""
    FW_SERVICES_DMZ_TCP=""
    FW_SERVICES_DMZ_UDP=""
    FW_SERVICES_DMZ_IP=""
    FW_SERVICES_INT_TCP="137 138 139"
    FW_SERVICES_INT_UDP="137 138 139"
    FW_SERVICES_INT_IP=""
    FW_SERVICES_QUICK_TCP=""
    FW_SERVICES_QUICK_UDP=""
    FW_SERVICES_QUICK_IP=""
    FW_TRUSTED_NETS=""
    FW_ALLOW_INCOMING_HIGHPORTS_TCP="yes"
    FW_ALLOW_INCOMING_HIGHPORTS_UDP="yes"
    FW_SERVICE_AUTODETECT="yes"
    FW_SERVICE_DNS="no"
    FW_SERVICE_DHCLIENT="no"
    FW_SERVICE_DHCPD="yes"
    FW_SERVICE_SQUID="no"
    FW_SERVICE_SAMBA="yes"
    FW_FORWARD=""
    FW_FORWARD_MASQ="0/0,192.168.0.2,tcp,2325 "

    I can get connected for a bit, then it drops me. Do I need to open up the ports
    via FW_SERVICES_INT_TCP and FW_SERVICES_EXT_TCP also? Is there a simple one
    step solution to allow all my windows pcs to play various games on the internet?
     Or do I have to do special rules for each and every machine and game in
    FW_FORWARD_MASQ? I could swear that when I used other tools in the past I could
    just open up a port and be done with it. Yet I'm having nothing but trouble
    with this. The weird thing is how some stuff works just fine. I got waste
    running pretty quickly, but I had to initiate the connection with my friend, the
    firewall blocked his attempt to connect to me, but once I connected to him
    things went back and forth just fine.

    -- 
    Keith Mickunas
    keith@mickunas.net
    I'll be deep in the cold, cold ground before I recognize Missourah! - Grandpa
    Simpson
    -------------------------------------------------
    This mail sent through IMP: http://horde.org/imp/
    -- 
    Check the headers for your unsubscription address
    For additional commands send e-mail to suse-linux-e-help@suse.com
    Also check the archives at http://lists.suse.com
    Please read the FAQs: suse-linux-e-faq@suse.com
    

  • Next message: Jim Norton: "Re: [SLE] Forcing 3Ware ATA module on IRQ 10"

    Relevant Pages

    • Re: Using Remote Desktop From an SBS Domain
      ... when you tried to RDP while attached directly to a port on your router? ... Internet to initiate an IP conversation with your computer. ... This situation is different than if you ran your own NAT connection sharing ...
      (microsoft.public.windows.server.sbs)
    • Re: [SLE] SuSEfirewall2 and games
      ... Now I have to figure out how to let my internal machines see the web site on the ... connection on the internal card to port 80. ... >> eth0 connected to the internet ...
      (SuSE)
    • Re: Using Remote Desktop From an SBS Domain
      ... I don't have much experience with this type of Internet access (at least not ... allows all "outbound" traffic from your private network to flow freely to ... UDP port (synchronize time with an external Network Time ... Hopefully next week I can attempt a connection while my ISP watches the ...
      (microsoft.public.windows.server.sbs)
    • Re: Yet another thread on the legality of port scanning
      ... Yet another thread on the legality of port scanning ... >> information transfer on the internet. ... >> is an acceptable connection in the absence of explicit permission? ... > pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • Re: 45 days STUCK LIKE CHUCK. DNS / Mx record cant recieve emails
      ... cable from the Comcast router and plug it into that machine, ... Yes router is connected directly into the internet nic / other nic ... You can test the connection from within the LAN, ... I'm thinking that leaves the NAT device blocking port 25. ...
      (microsoft.public.windows.server.sbs)